Описание
Security update for hplip
This update for hplip fixes the following issues
Security issues:
- CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031).
- CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023).
- CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024).
- hplip: unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS) (bsc#1245358).
Non security issues:
- Can't set up fax for HP OfficeJet 3830 (bsc#1257529).
- hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).
- Update to HPLIP 3.26.4.
Список пакетов
SUSE Linux Enterprise Server 12 SP5-LTSS
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:2228-1
- E-Mail link for SUSE-SU-2026:2228-1
- SUSE Security Ratings
- SUSE Bug 1245358
- SUSE Bug 1250481
- SUSE Bug 1257529
- SUSE Bug 1266023
- SUSE Bug 1266024
- SUSE Bug 1266031
- SUSE CVE CVE-2025-43023 page
- SUSE CVE CVE-2026-8631 page
- SUSE CVE CVE-2026-8632 page
Описание
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).
Затронутые продукты
Ссылки
- CVE-2025-43023
- SUSE Bug 1266031
Описание
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
Затронутые продукты
Ссылки
- CVE-2026-8631
- SUSE Bug 1266023
- SUSE Bug 1270233
Описание
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via operating system command injection.
Затронутые продукты
Ссылки
- CVE-2026-8632
- SUSE Bug 1266024