SUSE-SU-2026:4362-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264362-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4362-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4362-1
Upstream
CVE (10)
  • CVE-2026-91097
  • CVE-2026-91098
  • CVE-2026-91099
  • CVE-2026-91100
  • CVE-2026-91101
  • CVE-2026-91102
  • CVE-2026-91103
  • CVE-2026-91104
  • CVE-2026-91105
  • CVE-2026-91106
Related
Published
2026-09-28T15:00:40Z
Modified
2026-09-29T09:15:08Z
Summary
Security update for hplip
Details

This update for hplip fixes the following issues:

  • CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303).
  • CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304).
  • CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305).
  • CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306).
  • CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307).
  • CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308).
  • CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309).
  • CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313).
  • CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310).
  • CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314 bsc#1282051).

Changes for hplip:

  • Fix download of propietary plugin for 3.26.6
  • Update to HPLIP 3.26.6
  • Add support for the following new printers:
  • HP ScanJet Enterprise Flow N9000 sn1
  • HP ScanJet Enterprise Flow 9000 s1
  • HP ScanJet Pro 4200 s1
  • HP LaserJet Pro 4006dn printer
  • HP LaserJet Pro 4006dw printer
  • HP LaserJet Pro 4006n printer
  • HP LaserJet Pro 4002d printer
  • HP LaserJet Pro 4007dw printer
  • HP LaserJet Pro 4007n printer
  • HP LaserJet Pro 4008d
  • HP LaserJet Pro 4008dn
  • HP LaserJet Pro 4008dw
  • HP LaserJet Pro MFP 4112dw printer
  • HP LaserJet Pro MFP 4112fdn printer
  • HP LaserJet Pro MFP 4112fdw printer
  • HP LaserJet Pro MFP 4113dw printer
  • HP LaserJet Pro MFP 4113dwg printer
  • HP LaserJet Pro MFP 4113fdn printer
  • HP LaserJet Pro MFP 4113fdng printer
  • HP LaserJet Pro MFP 4113fdw printer
  • HP LaserJet Pro MFP 4113fdwg printer
  • HP LaserJet Pro MFP 4114dw
  • HP LaserJet Pro MFP 4114fdn
  • HP LaserJet Pro MFP 4114fdw
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 SP7
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150700.4.11.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip-devel":  "3.26.6-150700.4.11.1",
            "hplip-hpijs":  "3.26.6-150700.4.11.1",
            "hplip-sane":  "3.26.6-150700.4.11.1",
            "hplip-udev-rules":  "3.26.6-150700.4.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4362-1.json"
SUSE:Linux Enterprise Module for Desktop Applications 15 SP7
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150700.4.11.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150700.4.11.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4362-1.json"