critical
Security update for hplip
SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2229
This update for hplip fixes the following issues Security issues: - CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031). - CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023). - CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024). - Unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS). (bsc#1245358) - URI parameter injection via unsanitized USB serial number. (bsc#1209401) Non security issues: - Can't set up fax for HP OfficeJet 3830 (bsc#1257529). - hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481). - Update to HPLIP 3.26.4
-
Release DateJun 3 2026
-
ReferencesBugzilla: 1209401, 1245358, 1250481, 1257529, 1266023, 1266024, 1266031
CVEs: CVE-2025-43023, CVE-2026-8631, CVE-2026-8632 -
Typesecurity
-
Severitycritical
cloud_download Downloads
Desktop Applications Module 15.7 aarch64
-
Packages
Desktop Applications Module 15.7 ppc64le
-
Packages
Desktop Applications Module 15.7 s390x
-
Packages
Desktop Applications Module 15.7 x86_64
-
Packages