ELSA-2026-39976

ELSA-2026-39976 - hplip security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-07-16

Description


[3.23.12-10.5]
- RHEL-192007 CVE-2026-14544 hplip: Incomplete Fix for CVE-2026-8631

[3.23.12-10.4]
- Fix more leaks in hpcups

[3.23.12-10.3]
- OSH fixes after CVE-2026-8631

[3.23.12-10.2]
- CVE-2026-8631 hplip: Arbitrary code execution and privilege escalation via
integer overflow in hpcups

[3.23.12-10.1]
- CVE-2026-8632 hplip: Privilege escalation and arbitrary code execution
via OS command injection in Is_Process_Running()


Related CVEs


CVE-2026-14544

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) hplip-3.23.12-10.el10_2.5.src.rpmf798cdf30c3705dfa01b83362c8773570e53f02e8b47ee700975a0401d731f8b-ol10_aarch64_appstream
hplip-3.23.12-10.el10_2.5.aarch64.rpm57d6c20123c0f5154d82259dad77e4417fff293f046ab3d2d3bc215227db4d4f-ol10_aarch64_appstream
hplip-common-3.23.12-10.el10_2.5.aarch64.rpm5c95593c7f3855fa057f1bc958e55db6317d2ed78989c1e2fd3fbe4db5be1ef3-ol10_aarch64_appstream
hplip-libs-3.23.12-10.el10_2.5.aarch64.rpm64d57ed0ce01d142823f862b2d8ba18d2d3cedc468062071fd419d951a9299ac-ol10_aarch64_appstream
libsane-hpaio-3.23.12-10.el10_2.5.aarch64.rpm5d57f7269c505c0706047a460d3f26b469d254e98fde62fd43860d08b795949a-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) hplip-3.23.12-10.el10_2.5.src.rpmf798cdf30c3705dfa01b83362c8773570e53f02e8b47ee700975a0401d731f8b-ol10_x86_64_appstream
hplip-3.23.12-10.el10_2.5.x86_64.rpm31d22d132b8786c3075a5fbf0eaf4b1fe2485118a3abe9a3049848109afb4735-ol10_x86_64_appstream
hplip-common-3.23.12-10.el10_2.5.x86_64.rpm03ac62ef49a5733b5ec49f10250e74372b38e0b02c01473d0b3cd700a41a77bd-ol10_x86_64_appstream
hplip-libs-3.23.12-10.el10_2.5.x86_64.rpm9d51931faeb77d4ad684c005cf26dcd04f0695ccb9d456f312423820af2ef6cb-ol10_x86_64_appstream
libsane-hpaio-3.23.12-10.el10_2.5.x86_64.rpme5c72e6e3356a2421ef872bdb58745bc16d8a79ca40cfc3c7d71ee14e480f570-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete