SUSE-SU-2026:4335-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264335-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4335-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4335-1
Upstream
CVE (10)
  • CVE-2026-91097
  • CVE-2026-91098
  • CVE-2026-91099
  • CVE-2026-91100
  • CVE-2026-91101
  • CVE-2026-91102
  • CVE-2026-91103
  • CVE-2026-91104
  • CVE-2026-91105
  • CVE-2026-91106
Related
Published
2026-09-24T08:37:31Z
Modified
2026-09-24T18:30:05Z
Summary
Security update for hplip
Details

This update for hplip fixes the following issues:

  • CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303).
  • CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304).
  • CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305).
  • CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306).
  • CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307).
  • CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308).
  • CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309).
  • CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313).
  • CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310).
  • CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314 bsc#1282051).

Changes for hplip:

  • Fix download of propietary plugin for 3.26.6
  • Update to HPLIP 3.26.6
  • Add support for the following new printers:
  • HP ScanJet Enterprise Flow N9000 sn1
  • HP ScanJet Enterprise Flow 9000 s1
  • HP ScanJet Pro 4200 s1
  • HP LaserJet Pro 4006dn printer
  • HP LaserJet Pro 4006dw printer
  • HP LaserJet Pro 4006n printer
  • HP LaserJet Pro 4002d printer
  • HP LaserJet Pro 4007dw printer
  • HP LaserJet Pro 4007n printer
  • HP LaserJet Pro 4008d
  • HP LaserJet Pro 4008dn
  • HP LaserJet Pro 4008dw
  • HP LaserJet Pro MFP 4112dw printer
  • HP LaserJet Pro MFP 4112fdn printer
  • HP LaserJet Pro MFP 4112fdw printer
  • HP LaserJet Pro MFP 4113dw printer
  • HP LaserJet Pro MFP 4113dwg printer
  • HP LaserJet Pro MFP 4113fdn printer
  • HP LaserJet Pro MFP 4113fdng printer
  • HP LaserJet Pro MFP 4113fdw printer
  • HP LaserJet Pro MFP 4113fdwg printer
  • HP LaserJet Pro MFP 4114dw
  • HP LaserJet Pro MFP 4114fdn
  • HP LaserJet Pro MFP 4114fdw
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS / hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-3.14.2

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-3.14.2",
            "hplip-devel":  "3.26.6-3.14.2",
            "hplip-hpijs":  "3.26.6-3.14.2",
            "hplip-sane":  "3.26.6-3.14.2",
            "hplip-udev-rules":  "3.26.6-3.14.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4335-1.json"

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-3.14.2

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-3.14.2",
            "hplip-devel":  "3.26.6-3.14.2",
            "hplip-hpijs":  "3.26.6-3.14.2",
            "hplip-sane":  "3.26.6-3.14.2",
            "hplip-udev-rules":  "3.26.6-3.14.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4335-1.json"