Source: net-snmp
Version: 5.9.3+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for net-snmp.

CVE-2026-89147[0]:
| Net-SNMP through 5.9.5.2 contains a denial of service vulnerability
| in the SMUX module where smux_accept() performs an unauthenticated
| blocking read without timeout on newly accepted connections. An
| unauthenticated remote client can connect to the SMUX listener and
| send no data, causing the single-threaded snmpd main loop to block
| indefinitely and suspend all SNMP processing.

There is [1], but it is not immediately clear if it has been
reporterdd upstream.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-89147
    https://www.cve.org/CVERecord?id=CVE-2026-89147
[1] https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb

Regards,
Salvatore

Reply via email to