Bug#1137374: marked as done (hplip: CVE-2026-8631 CVE-2026-8632)
"Debian Bug Tracking System" <[email protected]> Mon, 03 Aug 2026 15:49:02 +0000
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <handler.1137374.D1137374.17857720352827101.ackdone@bugs.debian.org> |
This is a multi-part message in MIME format... ------------=_1785772142-2828598-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Mon, 03 Aug 2026 15:47:12 +0000 with message-id <[email protected]> and subject line Bug#1137374: fixed in hplip 3.22.10+dfsg0-8.1+deb13u1 has caused the Debian Bug report #1137374, regarding hplip: CVE-2026-8631 CVE-2026-8632 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 1137374: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1137374 Debian Bug Tracking System Contact [email protected] with problems ------------=_1785772142-2828598-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 23 May 2026 07:49:47 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-10.0 required=4.0 tests=BAYES_00,FROMDEVELOPER, NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 23; hammy, 137; neutral, 37; spammy, 1. spammytokens:0.941-+--H*r:bugs.debian.org hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc, 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug Return-path: <[email protected]> Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96) (envelope-from <[email protected]>) id 1wQh7B-0001gI-26 for [email protected]; Sat, 23 May 2026 07:49:47 +0000 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Salvatore Bonaccorso <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: hplip: CVE-2026-8631 CVE-2026-8632 Message-ID: <[email protected]> X-Mailer: reportbug 13.2.0 Date: Sat, 23 May 2026 09:49:44 +0200 Delivered-To: [email protected] Source: hplip Version: 3.22.10+dfsg0-8.1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for hplip. CVE-2026-8631[0]: | A potential security vulnerability has been identified in the HP | Linux Imaging and Printing Software. This potential vulnerability | may allow escalation of privileges and/or arbitrary code execution | via an integer overflow in the hpcups processing path when handling | crafted print data. CVE-2026-8632[1]: | A potential security vulnerability has been identified in the HP | Linux Imaging and Printing Software. This potential vulnerability | may allow escalation of privileges and/or arbitrary code execution | via operating system command injection. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-8631 https://www.cve.org/CVERecord?id=CVE-2026-8631 [1] https://security-tracker.debian.org/tracker/CVE-2026-8632 https://www.cve.org/CVERecord?id=CVE-2026-8632 [2] https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118 Please adjust the affected versions in the BTS as needed. Regards, Salvatore ------------=_1785772142-2828598-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1137374-close) by bugs.debian.org; 3 Aug 2026 15:47:15 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-113.1 required=4.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER, MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS, USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 95; hammy, 150; neutral, 165; spammy, 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK, 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo Return-path: <[email protected]> Received: from mitropoulos.debian.org ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:47920) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wqusl-00BrSF-32 for [email protected]; Mon, 03 Aug 2026 15:47:15 +0000 Received: via submission from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified) by mitropoulos.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wqusj-00Gz8H-3C for [email protected]; Mon, 03 Aug 2026 15:47:13 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type: Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID :Content-Description:In-Reply-To:References; bh=jSySV4ne4/vFbi2vJPlhFnbHpt8mMLoMcwNbLQBZpcI=; b=kVGJRPJcV2rZ8oCeu/3rjQRD2V DIBz3VP7Y6DvDN0gzjUiuHJBHWq4JyrviF4iKH1V8T0pD8eDgjdZ6kHAARNlS634QnCEXuZ42clxr UX/ezkZRoHnJbD0SAR6LcfgevD2Sn+3RZKxieSJ19uy8OKkIgppupTboPqZsr5SYYz6mM27il0RaZ 4kJtcNdvIfkiRtdW2EtaWkhiE87P5OnxGLIhEjm2D2N9FFlfVnC+bLKoEvACX+MwOpxA6TkYbiUVm i1YYZOsMD+PKhFs5kpjn2pxkvW48Z+7esE5StUKBsLK3nBzgwNJkyda3dwopOF5yoot2vOYTe9+Ug N6VZ9c4w==; Received: from dak by fasolo.debian.org with local (Exim 4.98.2) (envelope-from <[email protected]>) id 1wqusi-00000006qob-3Q9Z; Mon, 03 Aug 2026 15:47:12 +0000 From: Debian FTP Masters <[email protected]> Reply-To: Thorsten Alteholz <[email protected]> To: [email protected] X-DAK: dak process-policy X-Debian: DAK X-Debian-Package: hplip Debian: DAK Debian-Changes: hplip_3.22.10+dfsg0-8.1+deb13u1_source.changes Debian-Source: hplip Debian-Version: 3.22.10+dfsg0-8.1+deb13u1 Debian-Architecture: source Debian-Suite: proposed-updates Debian-Archive-Action: accept MIME-Version: 1.0 Subject: Bug#1137374: fixed in hplip 3.22.10+dfsg0-8.1+deb13u1 Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============6669575100282068470==" Message-Id: <[email protected]> Date: Mon, 03 Aug 2026 15:47:12 +0000 --===============6669575100282068470== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Source: hplip Source-Version: 3.22.10+dfsg0-8.1+deb13u1 Done: Thorsten Alteholz <[email protected]> We believe that the bug you reported is fixed in the latest version of hplip, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Thorsten Alteholz <[email protected]> (supplier of updated hplip package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 25 Jul 2026 17:39:02 +0200 Source: hplip Architecture: source Version: 3.22.10+dfsg0-8.1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: Debian Printing Team <[email protected]> Changed-By: Thorsten Alteholz <[email protected]> Closes: 1137374 Changes: hplip (3.22.10+dfsg0-8.1+deb13u1) trixie-security; urgency=3Dhigh . * CVE-2026-8631 (Closes: #1137374) a potential security vulnerability might allow escalation of privileges and/or arbitrary code execution when handling crafted print data. * CVE-2026-8632 a potential security vulnerability might allow escalation of privileges and/or arbitrary code execution via operating system command injection. * with the help of Marc Deslauriers from Ubuntu, patches are extracted from hplip 3.26.4 Checksums-Sha1: ba25177fee8cd2de1ce145b4b87e60e8f3b61869 3276 hplip_3.22.10+dfsg0-8.1+deb13u= 1.dsc 7420f1d2ad61f86c9ac7db122f82ce59c8b0ad12 151068 hplip_3.22.10+dfsg0-8.1+deb1= 3u1.debian.tar.xz 28942d9fa663e7fcfce32acb06a5c49b4df0d9aa 9473 hplip_3.22.10+dfsg0-8.1+deb13u= 1_source.buildinfo Checksums-Sha256: c8850e71d645d676e0252329f12caa6e22fda98af4e902b082e7376c6c6a800b 3276 hplip_= 3.22.10+dfsg0-8.1+deb13u1.dsc 5cd79967b76cfbc9902f530b5986b2bf1721a4d8b7bb3b6a437f15782703c547 151068 hpli= p_3.22.10+dfsg0-8.1+deb13u1.debian.tar.xz f9047a5c3fe6e4a0f7300937955b9105454691d7cad83c62d1d184fddc428457 9473 hplip_= 3.22.10+dfsg0-8.1+deb13u1_source.buildinfo Files: fc0ba81f01a9ef5996f3858be594fcf8 3276 utils optional hplip_3.22.10+dfsg0-8.1= +deb13u1.dsc 28558d9f552b143063cb91d263e55b50 151068 utils optional hplip_3.22.10+dfsg0-8= .1+deb13u1.debian.tar.xz 4c3e08b8b04795b73dff8ee55aea748a 9473 utils optional hplip_3.22.10+dfsg0-8.1= +deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmplz0ZfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR9GgEACPV/7HDGhBjTVy9zLBOXeuP1s2xhG6 MqXGs2+7fc/WfH+bGgEe1QOiqE6Xm9l0CCY0FnV+oaOhDhzcmmBToDyibmlyCYL8 5FzFbeu3LzWt5d8F8OH/1qSAvcad/mf0aBYzWnlP6MPNlod/GCW0E5v9J2y8uCcq d95tz7sy2s4QzcmPdlD8Q4GwyFmUlP3apkKJWXBu5aBoQcMBi29jo0SFG6B4mmM0 rxIEpHPCnfloBwr77XKdr1jNAcbiSZRgqCEAq/+Z7rKIC20eJQ9a6wiJ4rOb9Ypw AoTfIJGtM5sANy1OnUdM4rf1X5+yO3U3CXM32hZPQEV7UKG3Pi5+h+Of8pFXnDPP ZJPvj2JAs72JeFM2GwIRt1uPgFxsGdVt0P8FIQgA0AtpcsVvANTT92anHC4WWzyR PGcHZg7gr4mULcLN+if6nyUdLCUyr1lq4POeexeJtslGU9MMXTx4aLmSdmdj2vMG jCM24Sim6k+K9kazYqD2T+TsDxgwg/o21SjZ6+WAXxAsMQrW8q/bXFhiY7W8alF/ qLPQ4defjpA+DA7z8hO/PJ8FO47c3g0oACsC/6LosQfj37fvS8Yi/tf3oR2otyQq Jph1DrpyGLLP4nVJcf6j+tEG/cx8ixeDDDxdfbfZXWmL5vabVFYG++TwMPnNvpyu WJMvO8V82E/M+A=3D=3D =3Dup9b -----END PGP SIGNATURE----- --===============6669575100282068470== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanC4AAAKCRCb9qggYcy5 IQlZAP0eTWbkGb2NUhW4BrVOXhC6JAownMCmZm173JMnBQcEEQEArtSC+w+xXnqZ ybvRANmk4/eJH8PBZURlN9Ep+0zI/Ag= =+I88 -----END PGP SIGNATURE----- --===============6669575100282068470==-- ------------=_1785772142-2828598-0--