Security update for hplip
| Announcement ID: | SUSE-SU-2026:2228-1 |
|---|---|
| Release Date: | 2026-06-03T08:07:01Z |
| Rating: | critical |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves three vulnerabilities and has three security fixes can now be installed.
Description:
This update for hplip fixes the following issues
Security issues:
- CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031).
- CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023).
- CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024).
- hplip: unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS) (bsc#1245358).
Non security issues:
- Can't set up fax for HP OfficeJet 3830 (bsc#1257529).
- hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).
- Update to HPLIP 3.26.4.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server 12 SP5 LTSS
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2228=1 -
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2228=1
Package List:
-
SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64)
- hplip-hpijs-3.26.4-3.8.1
- hplip-3.26.4-3.8.1
- hplip-hpijs-debuginfo-3.26.4-3.8.1
- hplip-sane-3.26.4-3.8.1
- hplip-udev-rules-3.26.4-3.8.1
- hplip-debuginfo-3.26.4-3.8.1
- hplip-devel-3.26.4-3.8.1
- hplip-debugsource-3.26.4-3.8.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64)
- hplip-sane-debuginfo-3.26.4-3.8.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64)
- hplip-hpijs-3.26.4-3.8.1
- hplip-3.26.4-3.8.1
- hplip-hpijs-debuginfo-3.26.4-3.8.1
- hplip-sane-3.26.4-3.8.1
- hplip-sane-debuginfo-3.26.4-3.8.1
- hplip-udev-rules-3.26.4-3.8.1
- hplip-debuginfo-3.26.4-3.8.1
- hplip-devel-3.26.4-3.8.1
- hplip-debugsource-3.26.4-3.8.1
References:
- https://www.suse.com/security/cve/CVE-2025-43023.html
- https://www.suse.com/security/cve/CVE-2026-8631.html
- https://www.suse.com/security/cve/CVE-2026-8632.html
- https://bugzilla.suse.com/show_bug.cgi?id=1245358
- https://bugzilla.suse.com/show_bug.cgi?id=1250481
- https://bugzilla.suse.com/show_bug.cgi?id=1257529
- https://bugzilla.suse.com/show_bug.cgi?id=1266023
- https://bugzilla.suse.com/show_bug.cgi?id=1266024
- https://bugzilla.suse.com/show_bug.cgi?id=1266031