{"id":"openSUSE-SU-2026:20858-1","summary":"Security update for hplip","details":"This update for hplip fixes the following issues:\n\nChanges in hplip:\n\n- Update to HPLIP 3.26.4\n  * CVE-2026-8631: Fixed privileges escalation and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023)\n  * CVE-2026-8632: Fixed privileges escalation and/or arbitrary code execution via operating system command injection (bsc#1266024)\n\n- Add support for the following new printers:\n\n  * HP LaserJet Pro MFP 3106sdw\n  * HP LaserJet Pro MFP 3105sdw\n  * HP Envy 6500e series\n  * HP Envy 6500 series\n  * HP OfficeJet Pro 9730 Series\n  * HP OfficeJet Pro 9730e Series\n  * HP OfficeJet Pro 9720 Series\n  * HP OfficeJet Pro 9720e Series\n  * HP OfficeJet Pro 8130e All-in-One series\n  * HP OfficeJet Pro 8130 All-in-One series\n  * HP OfficeJet 8130e All-in-One series\n  * HP OfficeJet 8130 All-in-One series\n  * HP OfficeJet Pro 8120e All-in-One series\n  * HP OfficeJet Pro 8120 All-in-One series\n  * HP OfficeJet 8120e All-in-One series\n  * HP OfficeJet 8120 All-in-One series\n  * HP DeskJet Ink Advantage ultra 5800 All-in-One Printer series\n  * HP DeskJet Ink Advantage ultra 5100 All-in-One Printer series\n  * HP DeskJet 4300e All-in-One Printer series\n  * HP DeskJet Ink Advantage 4300 All-in-One Printer series\n  * HP DeskJet 4300 All-in-One Printer series\n  * HP DeskJet 2900e All-in-One Printer series\n  * HP DeskJet Ink Advantage 2900 All-in-One Printer series\n  * HP DeskJet 2900 All-in-One Printer series\n\n- Update to HPLIP 3.25.8\n\n- Added support for the following new Printers:\n  * HP LaserJet Enterprise Flow MFP 8601z\n  * HP LaserJet Enterprise 5501\n  * HP LaserJet Enterprise MFP 5601dn\n  * HP LaserJet Enterprise 6500dn\n  * HP LaserJet Enterprise 5501n\n  * HP LaserJet Enterprise MFP 5601\n  * HP LaserJet Enterprise 6500\n  * HP LaserJet Enterprise 5502dn\n  * HP LaserJet Enterprise MFP 5602dn\n  * HP LaserJet Enterprise 6500n\n  * HP LaserJet Enterprise 5502\n  * HP LaserJet Enterprise MFP 5602f\n  * HP LaserJet Enterprise 6501dn\n  * HP LaserJet Enterprise X50452dn\n  * HP LaserJet Enterprise Flow MFP 5602zfw\n  * HP LaserJet Enterprise 6501\n  * HP LaserJet Enterprise X50452\n  * HP LaserJet Enterprise MFP 5602\n  * HP LaserJet Enterprise X60257dn\n  * HP LaserJet Enterprise MFP X53052dn\n  * HP LaserJet Enterprise Flow MFP X530\n  * HP LaserJet Enterprise X60257\n  * HP LaserJet Enterprise MFP X53052\n  * HP LaserJet Enterprise X60357dn\n  * HP LaserJet Enterprise X60357\n  * HP LaserJet Enterprise MFP 6600dn\n  * HP LaserJet Enterprise Flow MFP 6600zfw\n  * HP LaserJet Enterprise MFP 6600\n  * HP LaserJet Enterprise Flow MFP 6600zfsw\n  * HP LaserJet Enterprise MFP X62757dn\n  * HP LaserJet Enterprise Flow MFP X62757zs\n  * HP LaserJet Enterprise MFP X62757\n  * DEX D50452dn\n  * DEX MFP D53052dn\n\n- Fix handling of readfp() and read_filke() for ConfigParser objects,\n  avoiding confusing error messages (lp#2139771)\n- Fix compiler warnings on SLE15\n- Fix \"Found No Section\" error with python (lp#2095776)\n\n- Fix PPD lookup by moving PPDs from manufacturer-PPDs/hplip-fax\n  to  manufacturer-PPDs/hplip/fax etc (boo#1257529)\n\n- Move more utilities from hplip-utils to hplip-base.\n  * hplip-base now contains all utilities that are not totally useless\n    and can run without the Qt GUI.\n\n- Update fix for support of new GPG key, as the key has now been\n  uploaded to GPG keyservers (lp#2120738)\n- This fixes CVE-2025-43023 (bsc#1266031)\n\n- Drop dependency on cups-ppdc. It isn't necessary, as PPD\n  generation on target system is done by cups-driverd.\n\n- The old and outdated 'hpijs' driver support is finally dropped\n  (the 'hpcups' driver is the default driver since 2009)\n  so that there is no need for foomatic-filters (boo#1250481)\n\n- Continue refactoring:\n  * move GUI tools to \"hplip-utils\" subpackage\n  * convert \"hplip\" into an empty metapackage that pulls in hplip-utils\n    and all drivers / PPDs (except hpijs PPDs).\n\n- Refactor package structure:\n  * hplip: full set of utilities. Pulls in almost all subpackages\n    to deliver the \"traditional\" hplip experience\n  * hplip-base: small set of basic utilities that can be run\n    without GUI. Includes hp-probe and hp-plugin\n  * hplip-cups: minimal package for printing, without PPDs or\n    setup helpers\n  * hplip-sane: scanning support (unchanged)\n  * hplip-driver-hpcups: hpcups.drv for generating hpcups PPDs on\n    the fly (requires ppdc). The functionality of this package is\n    similar to the old (misnamed) \"hplip-hpijs\" package.\n  * hplip-driver-hpijs: hpijs.drv for generating PPDs for the deprecated\n    hpijs / foomatic_rip filter. Note that this functionality was not part of\n    the late hplip-hpijs package, because upstream hasn't ship foomatic PPDs\n    since hplip 3.17.11.\n  * hplip-ppds-{hpcups,hpps,postscript,hpijs,fax,plugin}: static PPD\n    files for different printer types.\n    hplip-ppds-hpcups is an alternative to hplip-driver-hpcups.\n  * libhplip0: shared library package, used by hplip-cups and\n    hplip-sane\n  * hplip-common: configuration files and directories used by\n    all hplip packages.\n\n- Other spec file changes:\n  * Skip deprecated suse_update_desktop_file by default on TW\n  * Don't mess with sane configuration in udev rules\n  * Only the hpijs packages depend on foomatic-rip, which is only\n    provided by cups-filters-1.x. The other packages can be used\n    with cups-filters2.\n  * Remove Obsoletes: for ancient predecessor packages\n  * Remove outdated comments from spec file\n  * Shorten package descriptions\n  * Fix a couple of rpmlint issues\n\n- Fix printer probing using avahi (lp#2120947)\n","modified":"2026-06-03T08:30:27.379678807Z","published":"2026-06-01T16:17:43Z","related":["CVE-2025-43023","CVE-2026-8631","CVE-2026-8632"],"upstream":["CVE-2025-43023","CVE-2026-8631","CVE-2026-8632"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266023"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266031"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-43023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8632"}],"schema_version":"1.7.5"}