Source: net-snmp Version: 5.9.3+dfsg-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for net-snmp. CVE-2026-89147[0]: | Net-SNMP through 5.9.5.2 contains a denial of service vulnerability | in the SMUX module where smux_accept() performs an unauthenticated | blocking read without timeout on newly accepted connections. An | unauthenticated remote client can connect to the SMUX listener and | send no data, causing the single-threaded snmpd main loop to block | indefinitely and suspend all SNMP processing. There is [1], but it is not immediately clear if it has been reporterdd upstream. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-89147 https://www.cve.org/CVERecord?id=CVE-2026-89147 [1] https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb Regards, Salvatore

