Critical Vulnerabilities in SUSE HPLIP Affecting Multiple Systems

Critical Vulnerabilities in SUSE HPLIP Affecting Multiple Systems

First seen 4 Jun 2026, 22:11 UTC Linuxsecurity 95% similarity 72.0

Article Content

Browse articles
ThreatCluster

SUSE has released updates addressing critical vulnerabilities in the HPLIP software, impacting various HP printers. Key issues include CVE-2025-43023, which involves weak code signing leading to potential key spoofing, and CVE-2026-8631, which allows escalation of privileges through an integer overflow. Additionally, CVE-2026-8632 enables arbitrary code execution via command injection. An unauthenticated remote denial-of-service vulnerability in the SLP parser is also present. These vulnerabilities could allow attackers to execute arbitrary code or disrupt services on affected devices. The updates were released on June 2 and June 3, 2026, with critical ratings assigned to the vulnerabilities. Users are urged to apply the patches immediately to mitigate risks.

Key Points: • Critical vulnerabilities in HPLIP affect HP printers, with potential for code execution and DoS. • CVE-2025-43023 and CVE-2026-8631 are among the most severe issues identified. • Immediate patching is recommended to secure affected systems.

ThreatCluster AI

Timeline

2025-07-28
CVE-2025-43023 published
Weak code signing DSA key vulnerability disclosed, allowing potential key spoofing.
Linuxsecurity
2026-05-20
CVE-2026-8631 published
Vulnerability allowing escalation of privileges via integer overflow disclosed.
Linuxsecurity
2026-05-20
CVE-2026-8632 published
Arbitrary code execution vulnerability via command injection disclosed.
Linuxsecurity
2026-06-02
SUSE releases critical update for HPLIP
Update addresses multiple security vulnerabilities, including CVE-2025-43023 and CVE-2026-8631.
Linuxsecurity
2026-06-03
Second critical update for HPLIP released
Further updates released to address additional vulnerabilities including denial-of-service issues.
Linuxsecurity

Community

Browse all →