SUSE-SU-2026:2222-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262222-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2222-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2222-1
Upstream
CVE (3)
  • CVE-2025-43023
  • CVE-2026-8631
  • CVE-2026-8632
Related
Published
2026-06-02T08:40:54Z
Modified
2026-06-03T08:30:23Z
Summary
Security update for hplip
Details

This update for hplip fixes the following issues

Security issues:

  • CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031).
  • CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023).
  • CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024).
  • Unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS). (bsc#1245358)
  • URI parameter injection via unsanitized USB serial number. (bsc#1209401)

Non security issues:

  • Can't set up fax for HP OfficeJet 3830 (bsc#1257529).
  • hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).
  • Update to HPLIP 3.26.4
References

Affected packages