Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68615

Опубликовано: 22 дек. 2025
Источник: redhat
CVSS3: 9.8

Описание

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

A flaw was found in net-snmp. A remote attacker can trigger a buffer overflow in the snmptrapd daemon by sending a specially crafted SNMP packet, causing the daemon to crash and resulting in a denial of service.

Отчет

This issue allows a remote and unauthenticated attacker to trigger a buffer overflow in the snmptrapd daemon by sending a specially crafted SNMP packet, causing it to crash, and resulting in a denial of service. However, as this is a buffer overflow issue, it can also cause memory corruption and the possibility of arbitrary code execution is not discarded. Note that SNMP ports are not recommended to be open to public networks, limiting the exposure of this issue. Additionally, default Red Hat Enterprise Linux security features such as SELinux enforcement, Address Space Layout Randomization (ASLR) and memory protections reduce the possibility of exploitation. Due to these reasons, this flaw has been rated with an important severity.

Меры по смягчению последствий

Make sure to restrict network traffic to the snmptrapd daemon using firewall rules to allow connections only from known and trusted users and that SNMP ports are not open to public networks. This will limit the exposure of this issue and reduce the likelihood of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6net-snmpWill not fix
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10net-snmpFixedRHSA-2026:066815.01.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportnet-snmpFixedRHSA-2026:081019.01.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportnet-snmpFixedRHSA-2026:092621.01.2026
Red Hat Enterprise Linux 8net-snmpFixedRHSA-2026:075019.01.2026
Red Hat Enterprise Linux 8net-snmpFixedRHSA-2026:075019.01.2026
Red Hat Enterprise Linux 8.2 Advanced Update Supportnet-snmpFixedRHSA-2026:085020.01.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportnet-snmpFixedRHSA-2026:085220.01.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onnet-snmpFixedRHSA-2026:085220.01.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2424618net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

CVSS3: 9.8
nvd
3 месяца назад

net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

CVSS3: 9.8
msrc
3 месяца назад

Net-SNMP snmptrapd crash

CVSS3: 9.8
debian
3 месяца назад

net-snmp is a SNMP application library, tools and daemon. Prior to ver ...

suse-cvrf
2 месяца назад

Security update for net-snmp

9.8 Critical

CVSS3