CVE-2026-8631
A critical flaw in HP's Linux Imaging and Printing Software lets attackers craft print jobs that trigger an integer overflow, potentially giving them elevated privileges or the ability to run arbitrary code. The bug is in the hpcups processing path and could be exploited by anyone who can send print data to the affected system. No public exploit is known, but the vulnerability is severe enough to warrant immediate attention.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
HP Linux Imaging and Printing Software (all versions) on Linux systems.
Real-world impact
An attacker who can send malicious print data could gain root privileges or execute arbitrary code on the target machine, compromising the entire system.
Why this severity
The CVSS score of 9.3 reflects the vulnerability's high impact on confidentiality, integrity, and availability, combined with no authentication or user interaction required. The integer overflow can be triggered remotely, giving attackers full control.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 20, 2026 · May 20, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 9h agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- support.hp.com/us-en/document/ish_14942099…vendor advisory
- access.redhat.com/errata/RHSA-2026:26228
- access.redhat.com/errata/RHSA-2026:26297
- access.redhat.com/errata/RHSA-2026:26335
- access.redhat.com/errata/RHSA-2026:48171
- access.redhat.com/errata/RHSA-2026:48586
- access.redhat.com/errata/RHSA-2026:48603
- access.redhat.com/errata/RHSA-2026:48606
- access.redhat.com/errata/RHSA-2026:48959
- access.redhat.com/errata/RHSA-2026:48960
- access.redhat.com/errata/RHSA-2026:48961
- access.redhat.com/security/cve/CVE-2026-8631
- bugzilla.redhat.com/show_bug.cgi
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2…