| Name | CVE-2026-89147 |
| Description | Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1147442 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| net-snmp (PTS) | bookworm, bookworm (security) | 5.9.3+dfsg-2+deb12u1 | vulnerable |
| trixie (security), trixie | 5.9.4+dfsg-2+deb13u1 | vulnerable |
| forky, sid | 5.9.5.2+dfsg-3 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| net-snmp | source | (unstable) | 5.9.5.2+dfsg-3 | | | 1147442 |
Notes
[trixie] - net-snmp <no-dsa> (Minor issue)
[bookworm] - net-snmp <postponed> (Minor issue, DoS)
https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb