Red Hat Product Errata RHSA-2026:48586 - Security Advisory Issued: 2026-07-30 Updated: 2026-07-30 RHSA-2026:48586 - Security Advisory Overview Updated Packages Synopsis Important: hplip security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for hplip is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals. Security Fix(es): HPLIP: HPLIP: Privilege escalation and arbitrary code execution via operating system command injection (CVE-2026-8632) HPLIP: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups (CVE-2026-8631) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2480297 - CVE-2026-8632 HPLIP: HPLIP: Privilege escalation and arbitrary code execution via operating system command injection BZ - 2480300 - CVE-2026-8631 HPLIP: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups CVEs CVE-2026-8631 CVE-2026-8632 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM hplip-3.21.2-6.el9_4.1.src.rpm SHA-256: c77697dd1e3d0258553c14170647e204bd95ea74f055c232b077eb258c5c68f1 x86_64 hplip-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 2a55240edc83bf84134bfd6d99f6e916731cf490abd34610c2f08c8412576482 hplip-common-3.21.2-6.el9_4.1.i686.rpm SHA-256: e3f134c722e830237acc7f776ed8cc39c0d3f1acf18ca09f1e7ec81484e2ebbc hplip-common-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 96aab0243beeadbe73f7681c35b426b84aebec8af708026d04c52f27281e7890 hplip-debuginfo-3.21.2-6.el9_4.1.i686.rpm SHA-256: 15039ca3cf9bf58ac0c9e2deef437bc852c8820fc73815c57868eab290671226 hplip-debuginfo-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 208db376a8f823d283c0e5f0e3fc646429e35d70c692dfbace7d683e4c78153c hplip-debugsource-3.21.2-6.el9_4.1.i686.rpm SHA-256: d513f7d202d230437ca898b9aa060d14d0a951f5982efbe3b3d23543d7221219 hplip-debugsource-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: dee589ab36d36224b256296f774df51365ee9aec978f287c5a047d51f1de9d30 hplip-libs-3.21.2-6.el9_4.1.i686.rpm SHA-256: b8835e4a1e6da7fde2c4936503be672fe7e0892d7234b539742e10ec9c65227b hplip-libs-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 5ee5c13b93cf8f540591fe5e6d5e24b5c631174a10b353a8847ac73e0d199d32 hplip-libs-debuginfo-3.21.2-6.el9_4.1.i686.rpm SHA-256: 968d7fedd96921d65d0810e880ac4f75841d9b4378a448c66c506c79d60af84f hplip-libs-debuginfo-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 9bd7970fd1aced3eac25676f1bebe73cc23af2ad387a1fb9ccfe04ece459526e libsane-hpaio-3.21.2-6.el9_4.1.i686.rpm SHA-256: bf5e6acbb4f67ba43ef9e99668a699ad5ec4ddaf56f9f08d76ce59d32b1abf51 libsane-hpaio-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: d56a44eb946ba5fdc6aa1c80f96403f928759309c287f4198607fcceb545b2e9 libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.i686.rpm SHA-256: 3fc8e157ae1bbfcef3953b00e579e496403c6c8cb19eb537ea7e7c02732bedcb libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 383d607e782548b806d2f4519ca7430f4efe710d6f66c655235fb19850b92562 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM hplip-3.21.2-6.el9_4.1.src.rpm SHA-256: c77697dd1e3d0258553c14170647e204bd95ea74f055c232b077eb258c5c68f1 ppc64le hplip-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: 3d2dd904e18cc51203b14412d2b63dad44b3d6953934d7d4f150c0fb3bcd269e hplip-common-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: aa2e9bc6e952e033ff36a261bac4d5d3ce66f35b24fad91000937ad2bc98d5d5 hplip-debuginfo-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: 5151a8687ecf980bf45262949f2b3dbb3ca0088efe1b8843928e8cc50c47b14c hplip-debugsource-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: 4f39c7476b26162c9d9ff13fc7d2ba67bc1bc51f0b1a9fe4ce42224fa8fab6ac hplip-libs-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: d57dcadaa50f620ac03b6c453b77c158dec0fa9c396eb7cd2e94bd8f9f049aee hplip-libs-debuginfo-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: 0d966c339913ce67874f06287e10f8fca22a0ee52ee1cdb0a7fa69305fe6c9ef libsane-hpaio-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: e6708a6e69d1c7cb5453f67396561cca13d2966daccad50a61edbed86b8b341b libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.ppc64le.rpm SHA-256: e0d0226ff5b44a6c8aaf9a96ab4150ef052b0024e812aa01177812bd3fa78939 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM hplip-3.21.2-6.el9_4.1.src.rpm SHA-256: c77697dd1e3d0258553c14170647e204bd95ea74f055c232b077eb258c5c68f1 x86_64 hplip-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 2a55240edc83bf84134bfd6d99f6e916731cf490abd34610c2f08c8412576482 hplip-common-3.21.2-6.el9_4.1.i686.rpm SHA-256: e3f134c722e830237acc7f776ed8cc39c0d3f1acf18ca09f1e7ec81484e2ebbc hplip-common-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 96aab0243beeadbe73f7681c35b426b84aebec8af708026d04c52f27281e7890 hplip-debuginfo-3.21.2-6.el9_4.1.i686.rpm SHA-256: 15039ca3cf9bf58ac0c9e2deef437bc852c8820fc73815c57868eab290671226 hplip-debuginfo-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 208db376a8f823d283c0e5f0e3fc646429e35d70c692dfbace7d683e4c78153c hplip-debugsource-3.21.2-6.el9_4.1.i686.rpm SHA-256: d513f7d202d230437ca898b9aa060d14d0a951f5982efbe3b3d23543d7221219 hplip-debugsource-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: dee589ab36d36224b256296f774df51365ee9aec978f287c5a047d51f1de9d30 hplip-libs-3.21.2-6.el9_4.1.i686.rpm SHA-256: b8835e4a1e6da7fde2c4936503be672fe7e0892d7234b539742e10ec9c65227b hplip-libs-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 5ee5c13b93cf8f540591fe5e6d5e24b5c631174a10b353a8847ac73e0d199d32 hplip-libs-debuginfo-3.21.2-6.el9_4.1.i686.rpm SHA-256: 968d7fedd96921d65d0810e880ac4f75841d9b4378a448c66c506c79d60af84f hplip-libs-debuginfo-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 9bd7970fd1aced3eac25676f1bebe73cc23af2ad387a1fb9ccfe04ece459526e libsane-hpaio-3.21.2-6.el9_4.1.i686.rpm SHA-256: bf5e6acbb4f67ba43ef9e99668a699ad5ec4ddaf56f9f08d76ce59d32b1abf51 libsane-hpaio-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: d56a44eb946ba5fdc6aa1c80f96403f928759309c287f4198607fcceb545b2e9 libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.i686.rpm SHA-256: 3fc8e157ae1bbfcef3953b00e579e496403c6c8cb19eb537ea7e7c02732bedcb libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.x86_64.rpm SHA-256: 383d607e782548b806d2f4519ca7430f4efe710d6f66c655235fb19850b92562 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM hplip-3.21.2-6.el9_4.1.src.rpm SHA-256: c77697dd1e3d0258553c14170647e204bd95ea74f055c232b077eb258c5c68f1 aarch64 hplip-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: 41ecde85a393be3d5a7ab3ad3c73dc2940245696ce094745016fe211fade5e96 hplip-common-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: 396d6fa373cc1d7ead97aece4e910496f9399fc63509ea8c2af257414d80544e hplip-debuginfo-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: c92f7043f7703c2aaae0e97326caac5a7b9b1892232d8a908f01d3a50cf86c04 hplip-debugsource-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: 08c4302dd93085a718991d860d274fa93f741a728ef79126babf78d9c83b6b89 hplip-libs-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: 1ef78f307fc0c75f20888076ce37e6e8e124dd516c691938a4a15ff8bb3b77f8 hplip-libs-debuginfo-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: c8de749f82d6585f12aa5f9a394185c9501fb9cc1901aa98c5e0b160305b8b1d libsane-hpaio-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: 9e8bae74f395c7dfbb84796468714a5d5eeca6dee24287138ef9a175e857c613 libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.aarch64.rpm SHA-256: 70391c20fd57ad18375eb93ebd2698d205573759769985095b81b9ab397bdc35 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM hplip-3.21.2-6.el9_4.1.src.rpm SHA-256: c77697dd1e3d0258553c14170647e204bd95ea74f055c232b077eb258c5c68f1 s390x hplip-3.21.2-6.el9_4.1.s390x.rpm SHA-256: d5753126c3c30702055003848f04cc77d65df9603cd7736a35ddfe6f82035c66 hplip-common-3.21.2-6.el9_4.1.s390x.rpm SHA-256: e92dfad637a80568cb2e98c8b4969252294a2ca92c81153867b8ebf20edc713b hplip-debuginfo-3.21.2-6.el9_4.1.s390x.rpm SHA-256: e570ba6c439ac55fdc53fe89898605a4781fd9daf94abbdf9c224dd0f4cd4be0 hplip-debugsource-3.21.2-6.el9_4.1.s390x.rpm SHA-256: c3cfe83aebc2b5fac129e243fe47cbc59fa0d75411f66d1c6c17d4343fc85ded hplip-libs-3.21.2-6.el9_4.1.s390x.rpm SHA-256: 3a1dcc88889049f7d693ee8c5d99babb230fd7e069d8fc16481112082b4fceed hplip-libs-debuginfo-3.21.2-6.el9_4.1.s390x.rpm SHA-256: 3799aaed9336e77cab059ad51bcdb5cf7da1bad04047803dd190171aa656aac3 libsane-hpaio-3.21.2-6.el9_4.1.s390x.rpm SHA-256: 2b13abdd763b05b586172f74799f278ebe58bbfa392b76674c1de26b0ef7c47e libsane-hpaio-debuginfo-3.21.2-6.el9_4.1.s390x.rpm SHA-256: 87855b1ebcb1263ae71d6bdc333df032f58364de1d14df16ebeee6b0562f6f00 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SR
A critical integer overflow (CVE-2026-8631, CVSS 9.8) and a high-severity command injection flaw (CVE-2026-8632, CVSS 7.8) in HPLIP enable privilege escalation and arbitrary code execution. These vulnerabilities affect HPLIP versions prior to 3.26.4. The fix requires upgrading to HPLIP version 3.26.4.