SUSE-SU-2026:4371-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264371-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4371-1
Upstream
CVE (10)
  • CVE-2026-91097
  • CVE-2026-91098
  • CVE-2026-91099
  • CVE-2026-91100
  • CVE-2026-91101
  • CVE-2026-91102
  • CVE-2026-91103
  • CVE-2026-91104
  • CVE-2026-91105
  • CVE-2026-91106
Related
Published
2026-09-28T15:10:28Z
Modified
2026-09-29T09:15:07Z
Summary
Security update for hplip
Details

This update for hplip fixes the following issues:

  • CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303).
  • CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304).
  • CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305).
  • CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306).
  • CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307).
  • CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308).
  • CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309).
  • CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313).
  • CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310).
  • CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314 bsc#1282051).

Changes for hplip:

  • Fix download of propietary plugin for 3.26.6
  • Update to HPLIP 3.26.6
  • Add support for the following new printers:
  • HP ScanJet Enterprise Flow N9000 sn1
  • HP ScanJet Enterprise Flow 9000 s1
  • HP ScanJet Pro 4200 s1
  • HP LaserJet Pro 4006dn printer
  • HP LaserJet Pro 4006dw printer
  • HP LaserJet Pro 4006n printer
  • HP LaserJet Pro 4002d printer
  • HP LaserJet Pro 4007dw printer
  • HP LaserJet Pro 4007n printer
  • HP LaserJet Pro 4008d
  • HP LaserJet Pro 4008dn
  • HP LaserJet Pro 4008dw
  • HP LaserJet Pro MFP 4112dw printer
  • HP LaserJet Pro MFP 4112fdn printer
  • HP LaserJet Pro MFP 4112fdw printer
  • HP LaserJet Pro MFP 4113dw printer
  • HP LaserJet Pro MFP 4113dwg printer
  • HP LaserJet Pro MFP 4113fdn printer
  • HP LaserJet Pro MFP 4113fdng printer
  • HP LaserJet Pro MFP 4113fdw printer
  • HP LaserJet Pro MFP 4113fdwg printer
  • HP LaserJet Pro MFP 4114dw
  • HP LaserJet Pro MFP 4114fdn
  • HP LaserJet Pro MFP 4114fdw
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
hplip

Package

Name
hplip
Purl
pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.26.6-150400.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "hplip":  "3.26.6-150400.3.25.1",
            "hplip-devel":  "3.26.6-150400.3.25.1",
            "hplip-hpijs":  "3.26.6-150400.3.25.1",
            "hplip-sane":  "3.26.6-150400.3.25.1",
            "hplip-udev-rules":  "3.26.6-150400.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4371-1.json"