Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing. | |
| Title | Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX Read | |
| First Time appeared |
Net-snmp
Net-snmp net-snmp |
|
| Weaknesses | CWE-1088 CWE-400 |
|
| CPEs | cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Net-snmp
Net-snmp net-snmp |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-11T10:46:56.944Z
Updated: 2026-09-11T10:46:56.944Z
Reserved: 2026-09-11T01:23:34.216Z
Link: CVE-2026-89147
No data.
Status : Received
Published: 2026-09-11T11:16:58.040
Modified: 2026-09-11T11:16:58.040
Link: CVE-2026-89147
No data.