PT-2026-89827 · Net Snmp · Net-Snmp

·

CVE-2026-89147

·

Published

2026-09-11

·

Updated

2026-09-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89147

Affected Products

Net-Snmp