{"id":"SUSE-SU-2026:4364-1","summary":"Security update for hplip","details":"This update for hplip fixes the following issues:\n\n- CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303).\n- CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304).\n- CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305).\n- CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306).\n- CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307).\n- CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308).\n- CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309).\n- CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313).\n- CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310).\n- CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation,\n  denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314\n  bsc#1282051).\n\nChanges for hplip:\n\n- Fix download of propietary plugin for 3.26.6\n- Update to HPLIP 3.26.6\n- Add support for the following new printers:\n * HP ScanJet Enterprise Flow N9000 sn1\n * HP ScanJet Enterprise Flow 9000 s1\n * HP ScanJet Pro 4200 s1\n * HP LaserJet Pro 4006dn printer\n * HP LaserJet Pro 4006dw printer\n * HP LaserJet Pro 4006n printer\n * HP LaserJet Pro 4002d printer\n * HP LaserJet Pro 4007dw printer\n * HP LaserJet Pro 4007n printer\n * HP LaserJet Pro 4008d\n * HP LaserJet Pro 4008dn\n * HP LaserJet Pro 4008dw\n * HP LaserJet Pro MFP 4112dw printer\n * HP LaserJet Pro MFP 4112fdn printer\n * HP LaserJet Pro MFP 4112fdw printer\n * HP LaserJet Pro MFP 4113dw printer\n * HP LaserJet Pro MFP 4113dwg printer\n * HP LaserJet Pro MFP 4113fdn printer\n * HP LaserJet Pro MFP 4113fdng printer\n * HP LaserJet Pro MFP 4113fdw printer\n * HP LaserJet Pro MFP 4113fdwg printer\n * HP LaserJet Pro MFP 4114dw\n * HP LaserJet Pro MFP 4114fdn\n * HP LaserJet Pro MFP 4114fdw\n","modified":"2026-09-29T09:15:08.558711830Z","published":"2026-09-28T15:01:14Z","related":["CVE-2026-91097","CVE-2026-91098","CVE-2026-91099","CVE-2026-91100","CVE-2026-91101","CVE-2026-91102","CVE-2026-91103","CVE-2026-91104","CVE-2026-91105","CVE-2026-91106"],"upstream":["CVE-2026-91097","CVE-2026-91098","CVE-2026-91099","CVE-2026-91100","CVE-2026-91101","CVE-2026-91102","CVE-2026-91103","CVE-2026-91104","CVE-2026-91105","CVE-2026-91106"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264364-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281303"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281304"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281305"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281306"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281307"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281308"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281309"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1281314"},{"type":"REPORT","url":"https://bugzilla.suse.com/1282051"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91097"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91098"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91099"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91102"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91103"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91105"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-91106"}],"affected":[{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.6-150600.4.15.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-hpijs":"3.26.6-150600.4.15.1","hplip-sane":"3.26.6-150600.4.15.1","hplip-udev-rules":"3.26.6-150600.4.15.1","hplip":"3.26.6-150600.4.15.1","hplip-devel":"3.26.6-150600.4.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4364-1.json"}},{"package":{"name":"hplip","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/hplip&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.26.6-150600.4.15.1"}]}],"ecosystem_specific":{"binaries":[{"hplip-devel":"3.26.6-150600.4.15.1","hplip-hpijs":"3.26.6-150600.4.15.1","hplip-sane":"3.26.6-150600.4.15.1","hplip-udev-rules":"3.26.6-150600.4.15.1","hplip":"3.26.6-150600.4.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4364-1.json"}}],"schema_version":"1.9.0"}