rpm package
almalinux/net-snmp
pkg:rpm/almalinux/net-snmp
Vulnerabilities (9)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-68615 | Cri | 9.8 | < 1:5.9.4-15.el10_1.2 | 1:5.9.4-15.el10_1.2 | Dec 23, 2025 | net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2. | |
| CVE-2022-24810 | Med | 6.5 | < 1:5.9.1-13.el9_4.3 | 1:5.9.1-13.el9_4.3 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users shou | |
| CVE-2022-24809 | Med | 6.5 | < 1:5.9.1-13.el9_4.3 | 1:5.9.1-13.el9_4.3 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Us | |
| CVE-2022-24808 | Med | 6.5 | < 1:5.9.1-13.el9_4.3 | 1:5.9.1-13.el9_4.3 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contain | |
| CVE-2022-24807 | Med | 6.5 | < 1:5.9.1-13.el9_4.3 | 1:5.9.1-13.el9_4.3 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the | |
| CVE-2022-24806 | Med | 6.5 | < 1:5.9.1-13.el9_4.3 | 1:5.9.1-13.el9_4.3 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5. | |
| CVE-2022-24805 | Med | 6.5 | < 1:5.9.1-13.el9_4.3 | 1:5.9.1-13.el9_4.3 | Apr 16, 2024 | net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit | |
| CVE-2022-44793 | Med | 6.5 | < 1:5.9.1-9.el9 | 1:5.9.1-9.el9 | Nov 7, 2022 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| CVE-2022-44792 | Med | 6.5 | < 1:5.9.1-9.el9 | 1:5.9.1-9.el9 | Nov 7, 2022 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. |
- affected < 1:5.9.4-15.el10_1.2fixed 1:5.9.4-15.el10_1.2
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
- affected < 1:5.9.1-13.el9_4.3fixed 1:5.9.1-13.el9_4.3
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users shou
- affected < 1:5.9.1-13.el9_4.3fixed 1:5.9.1-13.el9_4.3
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Us
- affected < 1:5.9.1-13.el9_4.3fixed 1:5.9.1-13.el9_4.3
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contain
- affected < 1:5.9.1-13.el9_4.3fixed 1:5.9.1-13.el9_4.3
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the
- affected < 1:5.9.1-13.el9_4.3fixed 1:5.9.1-13.el9_4.3
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.
- affected < 1:5.9.1-13.el9_4.3fixed 1:5.9.1-13.el9_4.3
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit
- affected < 1:5.9.1-9.el9fixed 1:5.9.1-9.el9
handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
- affected < 1:5.9.1-9.el9fixed 1:5.9.1-9.el9
handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.