Denial of Service Vulnerability in Net-SNMP Product by Net-SNMP
CVE-2026-89147
8.7HIGH
What is CVE-2026-89147?
The vulnerability in the Net-SNMP product arises within the SMUX module, where the function smux_accept() allows unauthenticated remote clients to connect and induce a denial of service condition. This occurs due to an indefinite blocking read on newly accepted connections lacking a timeout feature. As a result, the main processing loop of the single-threaded snmpd becomes suspended, halting all SNMP processing and potentially affecting network monitoring and management operations.
Affected Version(s)
Net-SNMP 0 <= 5.9.5.2
