Bug#1137374: marked as done (hplip: CVE-2026-8631 CVE-2026-8632)

"Debian Bug Tracking System" <[email protected]> Mon, 03 Aug 2026 15:49:02 +0000
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <handler.1137374.D1137374.17857720352827101.ackdone@bugs.debian.org>
This is a multi-part message in MIME format...

------------=_1785772142-2828598-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Mon, 03 Aug 2026 15:47:12 +0000
with message-id <[email protected]>
and subject line Bug#1137374: fixed in hplip 3.22.10+dfsg0-8.1+deb13u1
has caused the Debian Bug report #1137374,
regarding hplip: CVE-2026-8631 CVE-2026-8632
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
1137374: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1137374
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1785772142-2828598-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 23 May 2026 07:49:47 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-10.0 required=4.0 tests=BAYES_00,FROMDEVELOPER,
	NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 23; hammy, 137; neutral, 37; spammy,
	1. spammytokens:0.941-+--H*r:bugs.debian.org
	hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc,
	0.000-+--X-Debbugs-Cc, 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug
Return-path: <[email protected]>
Received: via submission
	by buxtehude.debian.org with esmtp (Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wQh7B-0001gI-26
	for [email protected];
	Sat, 23 May 2026 07:49:47 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso <[email protected]>
To: Debian Bug Tracking System <[email protected]>
Subject: hplip: CVE-2026-8631 CVE-2026-8632
Message-ID: <[email protected]>
X-Mailer: reportbug 13.2.0
Date: Sat, 23 May 2026 09:49:44 +0200
Delivered-To: [email protected]

Source: hplip
Version: 3.22.10+dfsg0-8.1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for hplip.

CVE-2026-8631[0]:
| A potential security vulnerability has been identified in the HP
| Linux Imaging and Printing Software. This potential vulnerability
| may allow escalation of privileges and/or arbitrary code execution
| via an integer overflow in the hpcups processing path when handling
| crafted print data.


CVE-2026-8632[1]:
| A potential security vulnerability has been identified in the HP
| Linux Imaging and Printing Software. This potential vulnerability
| may allow escalation of privileges and/or arbitrary code execution
| via operating system command injection.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-8631
    https://www.cve.org/CVERecord?id=CVE-2026-8631
[1] https://security-tracker.debian.org/tracker/CVE-2026-8632
    https://www.cve.org/CVERecord?id=CVE-2026-8632
[2] https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

------------=_1785772142-2828598-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1137374-close) by bugs.debian.org; 3 Aug 2026 15:47:15 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.1 required=4.0 tests=BAYES_00,DKIM_SIGNED,
	DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,
	MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS,
	USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 95; hammy, 150; neutral, 165; spammy,
	0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
	0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
	0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: <[email protected]>
Received: from mitropoulos.debian.org ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:47920)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wqusl-00BrSF-32
	for [email protected];
	Mon, 03 Aug 2026 15:47:15 +0000
Received: via submission
	from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified)
	by mitropoulos.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wqusj-00Gz8H-3C
	for [email protected];
	Mon, 03 Aug 2026 15:47:13 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
	Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
	:Content-Description:In-Reply-To:References;
	bh=jSySV4ne4/vFbi2vJPlhFnbHpt8mMLoMcwNbLQBZpcI=; b=kVGJRPJcV2rZ8oCeu/3rjQRD2V
	DIBz3VP7Y6DvDN0gzjUiuHJBHWq4JyrviF4iKH1V8T0pD8eDgjdZ6kHAARNlS634QnCEXuZ42clxr
	UX/ezkZRoHnJbD0SAR6LcfgevD2Sn+3RZKxieSJ19uy8OKkIgppupTboPqZsr5SYYz6mM27il0RaZ
	4kJtcNdvIfkiRtdW2EtaWkhiE87P5OnxGLIhEjm2D2N9FFlfVnC+bLKoEvACX+MwOpxA6TkYbiUVm
	i1YYZOsMD+PKhFs5kpjn2pxkvW48Z+7esE5StUKBsLK3nBzgwNJkyda3dwopOF5yoot2vOYTe9+Ug
	N6VZ9c4w==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
	(envelope-from <[email protected]>)
	id 1wqusi-00000006qob-3Q9Z;
	Mon, 03 Aug 2026 15:47:12 +0000
From: Debian FTP Masters <[email protected]>
Reply-To: Thorsten Alteholz <[email protected]>
To: [email protected]
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: hplip
Debian: DAK
Debian-Changes: hplip_3.22.10+dfsg0-8.1+deb13u1_source.changes
Debian-Source: hplip
Debian-Version: 3.22.10+dfsg0-8.1+deb13u1
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1137374: fixed in hplip 3.22.10+dfsg0-8.1+deb13u1
Content-Type: multipart/signed; micalg="pgp-sha256";
 protocol="application/pgp-signature";
 boundary="===============6669575100282068470=="
Message-Id: <[email protected]>
Date: Mon, 03 Aug 2026 15:47:12 +0000

--===============6669575100282068470==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Source: hplip
Source-Version: 3.22.10+dfsg0-8.1+deb13u1
Done: Thorsten Alteholz <[email protected]>

We believe that the bug you reported is fixed in the latest version of
hplip, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thorsten Alteholz <[email protected]> (supplier of updated hplip package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 25 Jul 2026 17:39:02 +0200
Source: hplip
Architecture: source
Version: 3.22.10+dfsg0-8.1+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Printing Team <[email protected]>
Changed-By: Thorsten Alteholz <[email protected]>
Closes: 1137374
Changes:
 hplip (3.22.10+dfsg0-8.1+deb13u1) trixie-security; urgency=3Dhigh
 .
   * CVE-2026-8631 (Closes: #1137374)
     a potential security vulnerability might allow escalation of
     privileges and/or arbitrary code execution when handling crafted
     print data.
   * CVE-2026-8632
     a potential security vulnerability might allow escalation of
     privileges and/or arbitrary code execution via operating system
     command injection.
   * with the help of Marc Deslauriers from Ubuntu, patches are extracted
     from hplip 3.26.4
Checksums-Sha1:
 ba25177fee8cd2de1ce145b4b87e60e8f3b61869 3276 hplip_3.22.10+dfsg0-8.1+deb13u=
1.dsc
 7420f1d2ad61f86c9ac7db122f82ce59c8b0ad12 151068 hplip_3.22.10+dfsg0-8.1+deb1=
3u1.debian.tar.xz
 28942d9fa663e7fcfce32acb06a5c49b4df0d9aa 9473 hplip_3.22.10+dfsg0-8.1+deb13u=
1_source.buildinfo
Checksums-Sha256:
 c8850e71d645d676e0252329f12caa6e22fda98af4e902b082e7376c6c6a800b 3276 hplip_=
3.22.10+dfsg0-8.1+deb13u1.dsc
 5cd79967b76cfbc9902f530b5986b2bf1721a4d8b7bb3b6a437f15782703c547 151068 hpli=
p_3.22.10+dfsg0-8.1+deb13u1.debian.tar.xz
 f9047a5c3fe6e4a0f7300937955b9105454691d7cad83c62d1d184fddc428457 9473 hplip_=
3.22.10+dfsg0-8.1+deb13u1_source.buildinfo
Files:
 fc0ba81f01a9ef5996f3858be594fcf8 3276 utils optional hplip_3.22.10+dfsg0-8.1=
+deb13u1.dsc
 28558d9f552b143063cb91d263e55b50 151068 utils optional hplip_3.22.10+dfsg0-8=
.1+deb13u1.debian.tar.xz
 4c3e08b8b04795b73dff8ee55aea748a 9473 utils optional hplip_3.22.10+dfsg0-8.1=
+deb13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmplz0ZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR9GgEACPV/7HDGhBjTVy9zLBOXeuP1s2xhG6
MqXGs2+7fc/WfH+bGgEe1QOiqE6Xm9l0CCY0FnV+oaOhDhzcmmBToDyibmlyCYL8
5FzFbeu3LzWt5d8F8OH/1qSAvcad/mf0aBYzWnlP6MPNlod/GCW0E5v9J2y8uCcq
d95tz7sy2s4QzcmPdlD8Q4GwyFmUlP3apkKJWXBu5aBoQcMBi29jo0SFG6B4mmM0
rxIEpHPCnfloBwr77XKdr1jNAcbiSZRgqCEAq/+Z7rKIC20eJQ9a6wiJ4rOb9Ypw
AoTfIJGtM5sANy1OnUdM4rf1X5+yO3U3CXM32hZPQEV7UKG3Pi5+h+Of8pFXnDPP
ZJPvj2JAs72JeFM2GwIRt1uPgFxsGdVt0P8FIQgA0AtpcsVvANTT92anHC4WWzyR
PGcHZg7gr4mULcLN+if6nyUdLCUyr1lq4POeexeJtslGU9MMXTx4aLmSdmdj2vMG
jCM24Sim6k+K9kazYqD2T+TsDxgwg/o21SjZ6+WAXxAsMQrW8q/bXFhiY7W8alF/
qLPQ4defjpA+DA7z8hO/PJ8FO47c3g0oACsC/6LosQfj37fvS8Yi/tf3oR2otyQq
Jph1DrpyGLLP4nVJcf6j+tEG/cx8ixeDDDxdfbfZXWmL5vabVFYG++TwMPnNvpyu
WJMvO8V82E/M+A=3D=3D
=3Dup9b
-----END PGP SIGNATURE-----


--===============6669575100282068470==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCanC4AAAKCRCb9qggYcy5
IQlZAP0eTWbkGb2NUhW4BrVOXhC6JAownMCmZm173JMnBQcEEQEArtSC+w+xXnqZ
ybvRANmk4/eJH8PBZURlN9Ep+0zI/Ag=
=+I88
-----END PGP SIGNATURE-----

--===============6669575100282068470==--
------------=_1785772142-2828598-0--