Description
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Problem types
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Product status
>= 5.10.pre1, < 5.10.pre2
References
lists.debian.org/debian-lts-announce/2026/01/msg00000.html
www.openwall.com/lists/oss-security/2026/01/09/2
www.vicarius.io/...overflow-vulnerability-affecting-net-snmp
www.vicarius.io/...overflow-vulnerability-affecting-net-snmp
github.com/...t-snmp/security/advisories/GHSA-4389-rwqf-q9gq