
Cloud Vulnerability DB
A community-led vulnerabilities database
net-snmp before 5.8.1.pre1 contains a double free vulnerability in usm_free_usmStateReference in snmplib/snmpusm.c that can be triggered via an SNMPv3 GetBulk request (CVE Database, Ubuntu Security). This vulnerability was discovered in June 2020 and affects net-snmp packages shipped by multiple Linux distributions.
The vulnerability exists due to a double free condition in the usm_free_usmStateReference function when handling SNMPv3 GetBulk requests. The issue can be triggered by sending a specially crafted SNMPv3 GetBulk request with specific parameters like messageMaxSize. A proof-of-concept exploit command is: snmpbulkget -v3 -Cn1 -Cr1472 -l authPriv -u testuser -a SHA -A testpass -x AES -X testpass localhost 1.3.6.1.2.1.1.5 1.3.6.1.2.1.1.7 (Launchpad Bug).
When successfully exploited, this vulnerability results in a denial of service condition by causing the SNMP daemon to crash with a double free error. This affects the availability of SNMP services on the target system (Ubuntu Security).
The vulnerability requires authentication and can be exploited remotely by an authenticated user sending a specially crafted SNMPv3 GetBulk request. The vulnerability has been observed being exploited in real-world scenarios, particularly affecting monitoring systems like SolarWinds Orion NPM (Launchpad Bug).
The vulnerability is fixed in net-snmp version 5.8.1.pre1 and later. Users should upgrade to patched versions. Multiple Linux distributions have released security updates to address this issue. For Ubuntu 20.04 LTS, the fix is available in version 5.8+dfsg-2ubuntu2.1 (Ubuntu Security). The fix involved redesigning how the usmStateReference struct is manipulated internally, including adding a refcount mechanism (OSS Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."