Multiple vulnerabilities in Image Scanner Driver for Linux

Published: September 29, 2026, 13:00 JST (2026-09-29T13:00:00+09:00)

PFU Limited

[Vulnerability Overview]

An attacker who is able to log in to a Linux system on which the affected product is installed and who performs certain preparatory actions in advance may cause the following impacts:

  • Arbitrary OS commands may be executed on the system (CVE-2026-78229, CVSSv3 score 6.7 Medium)
  • Arbitrary files within the system may be overwritten (CVE-2026-81310, CVSSv3 score 6.6 Medium)
Vulnerability Information ID : PFU-2026-000001
Version : 1.00E
CVE ID(CWE ID) : CVE-2026-78229(CWE-78)
CVE-2026-81310(CWE-59)

[Affected Products / Versions]

  • Image Scanner Driver for Linux (fi Series)
    V2.0.0、V2.1.0、V2.1.1、V2.3.2、V2.5.0、V2.7.0、V2.7.1、V2.8.0、V2.8.1、V2.8.2
  • Image Scanner Driver for Linux (SP Series)
    V2.0.0、V2.1.0、V2.1.1、V2.1.1-4、V2.2.0、V2.2.1、V2.2.2、V2.3.0

[Mitigation]

Please update the product to the latest version from the download site.

Table 1. PFU Products and Services Requiring Mitigation for the Vulnerabilities

Product/service Download Sites and Other Resources
Image Scanner Driver for Linux(fi Series) https://www.pfu.ricoh.com/global/scanners/fi/dl/
Image Scanner Driver for Linux(SP Series) https://www.pfu.ricoh.com/global/scanners/fi/dl/index-sps.html

Acknowledgement:

PFU would like to thank Nir Yehoshua at Cipher Security Labs for reporting this vulnerability.

History:

2026-09-29 13:00:00+09:00:1.00E Initial public release