Your message dated Mon, 03 Aug 2026 15:47:12 +0000
with message-id <[email protected]>
and subject line Bug#1137374: fixed in hplip 3.22.10+dfsg0-8.1+deb13u1
has caused the Debian Bug report #1137374,
regarding hplip: CVE-2026-8631 CVE-2026-8632
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1137374: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137374
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: hplip
Version: 3.22.10+dfsg0-8.1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for hplip.

CVE-2026-8631[0]:
| A potential security vulnerability has been identified in the HP
| Linux Imaging and Printing Software. This potential vulnerability
| may allow escalation of privileges and/or arbitrary code execution
| via an integer overflow in the hpcups processing path when handling
| crafted print data.


CVE-2026-8632[1]:
| A potential security vulnerability has been identified in the HP
| Linux Imaging and Printing Software. This potential vulnerability
| may allow escalation of privileges and/or arbitrary code execution
| via operating system command injection.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-8631
    https://www.cve.org/CVERecord?id=CVE-2026-8631
[1] https://security-tracker.debian.org/tracker/CVE-2026-8632
    https://www.cve.org/CVERecord?id=CVE-2026-8632
[2] https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: hplip
Source-Version: 3.22.10+dfsg0-8.1+deb13u1
Done: Thorsten Alteholz <[email protected]>

We believe that the bug you reported is fixed in the latest version of
hplip, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thorsten Alteholz <[email protected]> (supplier of updated hplip package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 25 Jul 2026 17:39:02 +0200
Source: hplip
Architecture: source
Version: 3.22.10+dfsg0-8.1+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Printing Team <[email protected]>
Changed-By: Thorsten Alteholz <[email protected]>
Closes: 1137374
Changes:
 hplip (3.22.10+dfsg0-8.1+deb13u1) trixie-security; urgency=high
 .
   * CVE-2026-8631 (Closes: #1137374)
     a potential security vulnerability might allow escalation of
     privileges and/or arbitrary code execution when handling crafted
     print data.
   * CVE-2026-8632
     a potential security vulnerability might allow escalation of
     privileges and/or arbitrary code execution via operating system
     command injection.
   * with the help of Marc Deslauriers from Ubuntu, patches are extracted
     from hplip 3.26.4
Checksums-Sha1:
 ba25177fee8cd2de1ce145b4b87e60e8f3b61869 3276 
hplip_3.22.10+dfsg0-8.1+deb13u1.dsc
 7420f1d2ad61f86c9ac7db122f82ce59c8b0ad12 151068 
hplip_3.22.10+dfsg0-8.1+deb13u1.debian.tar.xz
 28942d9fa663e7fcfce32acb06a5c49b4df0d9aa 9473 
hplip_3.22.10+dfsg0-8.1+deb13u1_source.buildinfo
Checksums-Sha256:
 c8850e71d645d676e0252329f12caa6e22fda98af4e902b082e7376c6c6a800b 3276 
hplip_3.22.10+dfsg0-8.1+deb13u1.dsc
 5cd79967b76cfbc9902f530b5986b2bf1721a4d8b7bb3b6a437f15782703c547 151068 
hplip_3.22.10+dfsg0-8.1+deb13u1.debian.tar.xz
 f9047a5c3fe6e4a0f7300937955b9105454691d7cad83c62d1d184fddc428457 9473 
hplip_3.22.10+dfsg0-8.1+deb13u1_source.buildinfo
Files:
 fc0ba81f01a9ef5996f3858be594fcf8 3276 utils optional 
hplip_3.22.10+dfsg0-8.1+deb13u1.dsc
 28558d9f552b143063cb91d263e55b50 151068 utils optional 
hplip_3.22.10+dfsg0-8.1+deb13u1.debian.tar.xz
 4c3e08b8b04795b73dff8ee55aea748a 9473 utils optional 
hplip_3.22.10+dfsg0-8.1+deb13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmplz0ZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR9GgEACPV/7HDGhBjTVy9zLBOXeuP1s2xhG6
MqXGs2+7fc/WfH+bGgEe1QOiqE6Xm9l0CCY0FnV+oaOhDhzcmmBToDyibmlyCYL8
5FzFbeu3LzWt5d8F8OH/1qSAvcad/mf0aBYzWnlP6MPNlod/GCW0E5v9J2y8uCcq
d95tz7sy2s4QzcmPdlD8Q4GwyFmUlP3apkKJWXBu5aBoQcMBi29jo0SFG6B4mmM0
rxIEpHPCnfloBwr77XKdr1jNAcbiSZRgqCEAq/+Z7rKIC20eJQ9a6wiJ4rOb9Ypw
AoTfIJGtM5sANy1OnUdM4rf1X5+yO3U3CXM32hZPQEV7UKG3Pi5+h+Of8pFXnDPP
ZJPvj2JAs72JeFM2GwIRt1uPgFxsGdVt0P8FIQgA0AtpcsVvANTT92anHC4WWzyR
PGcHZg7gr4mULcLN+if6nyUdLCUyr1lq4POeexeJtslGU9MMXTx4aLmSdmdj2vMG
jCM24Sim6k+K9kazYqD2T+TsDxgwg/o21SjZ6+WAXxAsMQrW8q/bXFhiY7W8alF/
qLPQ4defjpA+DA7z8hO/PJ8FO47c3g0oACsC/6LosQfj37fvS8Yi/tf3oR2otyQq
Jph1DrpyGLLP4nVJcf6j+tEG/cx8ixeDDDxdfbfZXWmL5vabVFYG++TwMPnNvpyu
WJMvO8V82E/M+A==
=up9b
-----END PGP SIGNATURE-----

Attachment: pgptpbCWG0Wfj.pgp
Description: PGP signature


--- End Message ---

Reply via email to