HIGH
Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX Read
Published Sep 11, 2026
8.7
HIGHCVSS 4.0
EPSS 0.49%
Description
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing.
Affected products
-
- Version 0StatusaffectedConstraints<=5.9.5.2
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76036 Advisory
- https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb exploitthird-party-advisory
- https://github.com/net-snmp/net-snmp product
- https://github.com/net-snmp/net-snmp/blob/v5.9.5.2/agent/mibgroup/smux/smux.c technical-description
- https://www.vulncheck.com/advisories/net-snmp-through-5.9.5.2-denial-of-service-via-blocking-unauthenticated-smux-read third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-76036 | Advisory | |
| https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb | exploitthird-party-advisory | |
| https://github.com/net-snmp/net-snmp | product | |
| https://github.com/net-snmp/net-snmp/blob/v5.9.5.2/agent/mibgroup/smux/smux.c | technical-description | |
| https://www.vulncheck.com/advisories/net-snmp-through-5.9.5.2-denial-of-service-via-blocking-unauthenticated-smux-read | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 11, 2026
Updated Sep 24, 2026
Reserved Sep 11, 2026
Link CVE-2026-89147
CISA Vulnrichment
Updated Sep 15, 2026
ENISA EUVD
EUVD-2026-76036 Assigner VulnCheck
Published Sep 11, 2026
Updated Sep 24, 2026
Exploited since n/a
Link EUVD-2026-76036