Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2222-1

Опубликовано: 02 июн. 2026
Источник: suse-cvrf

Описание

Security update for hplip

This update for hplip fixes the following issues

Security issues:

  • CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031).
  • CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023).
  • CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024).
  • Unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS). (bsc#1245358)
  • URI parameter injection via unsanitized USB serial number. (bsc#1209401)

Non security issues:

  • Can't set up fax for HP OfficeJet 3830 (bsc#1257529).
  • hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).
  • Update to HPLIP 3.26.4

Список пакетов

SUSE Linux Enterprise Server 15 SP6-LTSS
hplip-3.26.4-150600.4.9.1
hplip-devel-3.26.4-150600.4.9.1
hplip-hpijs-3.26.4-150600.4.9.1
hplip-sane-3.26.4-150600.4.9.1
hplip-udev-rules-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
hplip-3.26.4-150600.4.9.1
hplip-devel-3.26.4-150600.4.9.1
hplip-hpijs-3.26.4-150600.4.9.1
hplip-sane-3.26.4-150600.4.9.1
hplip-udev-rules-3.26.4-150600.4.9.1

Описание

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-devel-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-hpijs-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-sane-3.26.4-150600.4.9.1

Ссылки

Описание

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-devel-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-hpijs-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-sane-3.26.4-150600.4.9.1

Ссылки

Описание

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.


Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-devel-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-hpijs-3.26.4-150600.4.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:hplip-sane-3.26.4-150600.4.9.1

Ссылки