Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLES12 / SLES_SAP12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4335-1 advisory.
- CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303).
- CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304).
- CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305).
- CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306).
- CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307).
- CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308).
- CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309).
- CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313).
- CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310).
- CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314 bsc#1282051).
Changes for hplip:
- Fix download of propietary plugin for 3.26.6
- Update to HPLIP 3.26.6
- Add support for the following new printers:
* HP ScanJet Enterprise Flow N9000 sn1
* HP ScanJet Enterprise Flow 9000 s1
* HP ScanJet Pro 4200 s1
* HP LaserJet Pro 4006dn printer
* HP LaserJet Pro 4006dw printer
* HP LaserJet Pro 4006n printer
* HP LaserJet Pro 4002d printer
* HP LaserJet Pro 4007dw printer
* HP LaserJet Pro 4007n printer
* HP LaserJet Pro 4008d
* HP LaserJet Pro 4008dn
* HP LaserJet Pro 4008dw
* HP LaserJet Pro MFP 4112dw printer
* HP LaserJet Pro MFP 4112fdn printer
* HP LaserJet Pro MFP 4112fdw printer
* HP LaserJet Pro MFP 4113dw printer
* HP LaserJet Pro MFP 4113dwg printer
* HP LaserJet Pro MFP 4113fdn printer
* HP LaserJet Pro MFP 4113fdng printer
* HP LaserJet Pro MFP 4113fdw printer
* HP LaserJet Pro MFP 4113fdwg printer
* HP LaserJet Pro MFP 4114dw
* HP LaserJet Pro MFP 4114fdn
* HP LaserJet Pro MFP 4114fdw
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected packages.
Plugin Details
File Name: suse_SU-2026-4335-1.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:hplip-devel, p-cpe:/a:novell:suse_linux:hplip-hpijs, p-cpe:/a:novell:suse_linux:hplip-sane, p-cpe:/a:novell:suse_linux:hplip-udev-rules, p-cpe:/a:novell:suse_linux:hplip
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 9/24/2026
Vulnerability Publication Date: 9/16/2026