{"id":"SUSE-SU-2026:2380-1","summary":"Security update for hplip","details":"This update for hplip fixes the following issues\n\nUpdate to HPLIP 3.26.4:\n\nSecurity issues:\n\n- CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious\n  software installation (bsc#1266031).\n- CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups\n  processing path (bsc#1266023).\n- CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection\n  (bsc#1266024).\n- unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS) (bsc#1245358).\n- URI parameter injection via unsanitized USB serial number (bsc#1209401).\n\nNon security issues:\n\n- Can't set up fax for HP OfficeJet 3830 (bsc#1257529).\n- hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481).\n\nChanges:\n\n- Add support for the following new printers:\n * HP LaserJet Pro MFP 3106sdw\n * HP LaserJet Pro MFP 3105sdw\n * HP Envy 6500e series\n * HP Envy 6500 series\n * HP OfficeJet Pro 9730 Series\n * HP OfficeJet Pro 9730e Series\n * HP OfficeJet Pro 9720 Series\n * HP OfficeJet Pro 9720e Series\n * HP OfficeJet Pro 8130e All-in-One series\n * HP OfficeJet Pro 8130 All-in-One series\n * HP OfficeJet 8130e All-in-One series\n * HP OfficeJet 8130 All-in-One series\n * HP OfficeJet Pro 8120e All-in-One series\n * HP OfficeJet Pro 8120 All-in-One series\n * HP OfficeJet 8120e All-in-One series\n * HP OfficeJet 8120 All-in-One series\n * HP DeskJet Ink Advantage ultra 5800 All-in-One Printer series\n * HP DeskJet Ink Advantage ultra 5100 All-in-One Printer series\n * HP DeskJet 4300e All-in-One Printer series\n * HP DeskJet Ink Advantage 4300 All-in-One Printer series\n * HP DeskJet 4300 All-in-One Printer series\n * HP DeskJet 2900e All-in-One Printer series\n * HP DeskJet Ink Advantage 2900 All-in-One Printer series\n * HP DeskJet 2900 All-in-One Printer series\n * HP LaserJet Enterprise Flow MFP 8601z\n * HP LaserJet Enterprise 5501\n * HP LaserJet Enterprise MFP 5601dn\n * HP LaserJet Enterprise 6500dn\n * HP LaserJet Enterprise 5501n\n * HP LaserJet Enterprise MFP 5601\n * HP LaserJet Enterprise 6500\n * HP LaserJet Enterprise 5502dn\n * HP LaserJet Enterprise MFP 5602dn\n * HP LaserJet Enterprise 6500n\n * HP LaserJet Enterprise 5502\n * HP LaserJet Enterprise MFP 5602f\n * HP LaserJet Enterprise 6501dn\n * HP LaserJet Enterprise X50452dn\n * HP LaserJet Enterprise Flow MFP 5602zfw\n * HP LaserJet Enterprise 6501\n * HP LaserJet Enterprise X50452\n * HP LaserJet Enterprise MFP 5602\n * HP LaserJet Enterprise X60257dn\n * HP LaserJet Enterprise MFP X53052dn\n * HP LaserJet Enterprise Flow MFP X530\n * HP LaserJet Enterprise X60257\n * HP LaserJet Enterprise MFP X53052\n * HP LaserJet Enterprise X60357dn\n * HP LaserJet Enterprise X60357\n * HP LaserJet Enterprise MFP 6600dn\n * HP LaserJet Enterprise Flow MFP 6600zfw\n * HP LaserJet Enterprise MFP 6600\n * HP LaserJet Enterprise Flow MFP 6600zfsw\n * HP LaserJet Enterprise MFP X62757dn\n * HP LaserJet Enterprise Flow MFP X62757zs\n * HP LaserJet Enterprise MFP X62757\n * DEX D50452dn\n * DEX MFP D53052dn\n * HP LaserJet Pro MFP M126a plus\n * HP LaserJet Pro MFP M126nw plus\n * HP LaserJet Pro MFP M126snw plus\n * HP Envy Photo 7200 series\n * HP Envy Photo 7900 series\n * HP OfficeJet Pro 9110 Series\n * HP OfficeJet 9120 Series\n * HP OfficeJet Pro 9120 Series\n * HP OfficeJet Pro 9130 Series\n * HP LaserJet Enterprise Flow MFP 8601z+\n * HP LaserJet Enterprise MFP 8601dn\n * HP Color LaserJet Enterprise MFP 8801dn\n * HP Color LaserJet Enterprise Flow MFP 8801z\n * HP Color LaserJet Enterprise Flow MFP 8801z+\n * HP LaserJet Enterprise 8501dn\n * HP LaserJet Enterprise 8501x\n * HP LaserJet Enterprise 8501x+\n * DEX MFP D826\n * DEX MFP D82640\n * DEX MFP D82650\n * DEX MFP D82660\n * DEX D50145\n * DEX MFP D42540\n * DEX MFP D52645\n * DEX Color D55745\n * DEX Color MFP D57945\n * DEX Color MFP D677\n * DEX Color MFP D67755\n * DEX Color MFP D67765\n * DEX Color MFP D877\n * DEX Color MFP D87740\n * DEX Color MFP D87750\n * DEX Color MFP D87760\n * DEX Color MFP D87770\n * DEX Color MFP D786\n * DEX Colour MFP D78625\n * DEX Color MFP D78630\n * DEX Color MFP D78635\n * DEX MFP D731\n * DEX MFP D73130\n * DEX MFP D73135\n * DEX MFP D73140\n","modified":"2026-06-13T08:00:05.449189076Z","published":"2026-06-11T16:15:29Z","related":["CVE-2025-43023","CVE-2026-8631","CVE-2026-8632"],"upstream":["CVE-2025-43023","CVE-2026-8631","CVE-2026-8632"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262380-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209401"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234745"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245358"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266023"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8632"}],"affected":[{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1","hplip":"3.26.4-150400.3.22.1","hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1","hplip":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip":"3.26.4-150400.3.22.1","hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1","hplip":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1","hplip":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1","hplip":"3.26.4-150400.3.22.1","hplip-devel":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1","hplip":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.4-150400.3.22.1"}]}],"ecosystem_specific":{"binaries":[{"hplip":"3.26.4-150400.3.22.1","hplip-devel":"3.26.4-150400.3.22.1","hplip-hpijs":"3.26.4-150400.3.22.1","hplip-sane":"3.26.4-150400.3.22.1","hplip-udev-rules":"3.26.4-150400.3.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2380-1.json"}}],"schema_version":"1.7.5"}