SUSE-SU-2026:2380-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262380-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2380-1
Upstream
CVE (3)
  • CVE-2025-43023
  • CVE-2026-8631
  • CVE-2026-8632
Related
Published
2026-06-11T16:15:29Z
Modified
2026-06-13T08:00:05Z
Summary
Security update for hplip
Details

This update for hplip fixes the following issues

Update to HPLIP 3.26.4:

Security issues:

  • CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031).
  • CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023).
  • CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024).
  • unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS) (bsc#1245358).
  • URI parameter injection via unsanitized USB serial number (bsc#1209401).

Non security issues:

  • Can't set up fax for HP OfficeJet 3830 (bsc#1257529).
  • hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).

Changes:

  • Add support for the following new printers:
  • HP LaserJet Pro MFP 3106sdw
  • HP LaserJet Pro MFP 3105sdw
  • HP Envy 6500e series
  • HP Envy 6500 series
  • HP OfficeJet Pro 9730 Series
  • HP OfficeJet Pro 9730e Series
  • HP OfficeJet Pro 9720 Series
  • HP OfficeJet Pro 9720e Series
  • HP OfficeJet Pro 8130e All-in-One series
  • HP OfficeJet Pro 8130 All-in-One series
  • HP OfficeJet 8130e All-in-One series
  • HP OfficeJet 8130 All-in-One series
  • HP OfficeJet Pro 8120e All-in-One series
  • HP OfficeJet Pro 8120 All-in-One series
  • HP OfficeJet 8120e All-in-One series
  • HP OfficeJet 8120 All-in-One series
  • HP DeskJet Ink Advantage ultra 5800 All-in-One Printer series
  • HP DeskJet Ink Advantage ultra 5100 All-in-One Printer series
  • HP DeskJet 4300e All-in-One Printer series
  • HP DeskJet Ink Advantage 4300 All-in-One Printer series
  • HP DeskJet 4300 All-in-One Printer series
  • HP DeskJet 2900e All-in-One Printer series
  • HP DeskJet Ink Advantage 2900 All-in-One Printer series
  • HP DeskJet 2900 All-in-One Printer series
  • HP LaserJet Enterprise Flow MFP 8601z
  • HP LaserJet Enterprise 5501
  • HP LaserJet Enterprise MFP 5601dn
  • HP LaserJet Enterprise 6500dn
  • HP LaserJet Enterprise 5501n
  • HP LaserJet Enterprise MFP 5601
  • HP LaserJet Enterprise 6500
  • HP LaserJet Enterprise 5502dn
  • HP LaserJet Enterprise MFP 5602dn
  • HP LaserJet Enterprise 6500n
  • HP LaserJet Enterprise 5502
  • HP LaserJet Enterprise MFP 5602f
  • HP LaserJet Enterprise 6501dn
  • HP LaserJet Enterprise X50452dn
  • HP LaserJet Enterprise Flow MFP 5602zfw
  • HP LaserJet Enterprise 6501
  • HP LaserJet Enterprise X50452
  • HP LaserJet Enterprise MFP 5602
  • HP LaserJet Enterprise X60257dn
  • HP LaserJet Enterprise MFP X53052dn
  • HP LaserJet Enterprise Flow MFP X530
  • HP LaserJet Enterprise X60257
  • HP LaserJet Enterprise MFP X53052
  • HP LaserJet Enterprise X60357dn
  • HP LaserJet Enterprise X60357
  • HP LaserJet Enterprise MFP 6600dn
  • HP LaserJet Enterprise Flow MFP 6600zfw
  • HP LaserJet Enterprise MFP 6600
  • HP LaserJet Enterprise Flow MFP 6600zfsw
  • HP LaserJet Enterprise MFP X62757dn
  • HP LaserJet Enterprise Flow MFP X62757zs
  • HP LaserJet Enterprise MFP X62757
  • DEX D50452dn
  • DEX MFP D53052dn
  • HP LaserJet Pro MFP M126a plus
  • HP LaserJet Pro MFP M126nw plus
  • HP LaserJet Pro MFP M126snw plus
  • HP Envy Photo 7200 series
  • HP Envy Photo 7900 series
  • HP OfficeJet Pro 9110 Series
  • HP OfficeJet 9120 Series
  • HP OfficeJet Pro 9120 Series
  • HP OfficeJet Pro 9130 Series
  • HP LaserJet Enterprise Flow MFP 8601z+
  • HP LaserJet Enterprise MFP 8601dn
  • HP Color LaserJet Enterprise MFP 8801dn
  • HP Color LaserJet Enterprise Flow MFP 8801z
  • HP Color LaserJet Enterprise Flow MFP 8801z+
  • HP LaserJet Enterprise 8501dn
  • HP LaserJet Enterprise 8501x
  • HP LaserJet Enterprise 8501x+
  • DEX MFP D826
  • DEX MFP D82640
  • DEX MFP D82650
  • DEX MFP D82660
  • DEX D50145
  • DEX MFP D42540
  • DEX MFP D52645
  • DEX Color D55745
  • DEX Color MFP D57945
  • DEX Color MFP D677
  • DEX Color MFP D67755
  • DEX Color MFP D67765
  • DEX Color MFP D877
  • DEX Color MFP D87740
  • DEX Color MFP D87750
  • DEX Color MFP D87760
  • DEX Color MFP D87770
  • DEX Color MFP D786
  • DEX Colour MFP D78625
  • DEX Color MFP D78630
  • DEX Color MFP D78635
  • DEX MFP D731
  • DEX MFP D73130
  • DEX MFP D73135
  • DEX MFP D73140
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.4-150400.3.22.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.4-150400.3.22.1",
            "hplip-devel":  "3.26.4-150400.3.22.1",
            "hplip-hpijs":  "3.26.4-150400.3.22.1",
            "hplip-sane":  "3.26.4-150400.3.22.1",
            "hplip-udev-rules":  "3.26.4-150400.3.22.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"