RHSA-2026:48959: Important: hplip security update
Important: hplip security update
Other sources
The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals.Security Fix(es): HPLIP: HPLIP: Privilege escalation and arbitrary code execution via operating system command injection (CVE-2026-8632) HPLIP: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups (CVE-2026-8631) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/hplipto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/hplip-commonto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/hplip-debuginfoto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/hplip-debugsourceto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/hplip-guito a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/hplip-libsto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/hplip-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/libsane-hpaioto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1 - Upgrade
Upgrade
redhat/libsane-hpaio-debuginfoto a version that resolves this vulnerability.Fixed in 3.18.4-9.el8_8.1
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:48959?
The severity of RHSA-2026:48959 is classified as high, with a score of 7.
What is the main issue addressed in RHSA-2026:48959?
RHSA-2026:48959 addresses a security vulnerability that allows for privilege escalation and arbitrary code execution within HPLIP.
How do I fix RHSA-2026:48959?
To fix RHSA-2026:48959, update your hplip packages to the latest version provided by Red Hat.
Which software is affected by RHSA-2026:48959?
The affected software includes redhat/hplip, redhat/hplip-common, redhat/hplip-libs, and related packages.
What types of vulnerabilities are included in RHSA-2026:48959?
RHSA-2026:48959 includes vulnerabilities related to Integer Overflow and Command Injection.