{"id":"SUSE-SU-2026:2229-1","summary":"Security update for hplip","details":"This update for hplip fixes the following issues\n\nSecurity issues:\n\n- CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious\n  software installation (bsc#1266031).\n- CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups\n  processing path (bsc#1266023).\n- CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection\n  (bsc#1266024).\n- Unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS). (bsc#1245358)\n- URI parameter injection via unsanitized USB serial number. (bsc#1209401)\n\nNon security issues:\n\n- Can't set up fax for HP OfficeJet 3830 (bsc#1257529).\n- hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).\n- Update to HPLIP 3.26.4\n","modified":"2026-06-05T18:24:09.120388124Z","published":"2026-06-03T08:07:17Z","related":["CVE-2025-43023","CVE-2026-8631","CVE-2026-8632"],"upstream":["CVE-2025-43023","CVE-2026-8631","CVE-2026-8632"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262229-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209401"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245358"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266023"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8632"}],"schema_version":"1.7.5"}