CVE-2026-89147

Public on 2026-09-11
Modified on 2026-09-11
Description
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core net-snmp Pending Fix
Amazon Linux 2023 net-snmp Pending Fix
Amazon Linux 2027 Preview net-snmp Pending Fix
Amazon Linux 2023 perl-Net-SNMP Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H