Bug 34979 - net-snmp new security issue CVE-2025-68615
Summary: net-snmp new security issue CVE-2025-68615
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2026-01-12 09:16 CET by Nicolas Salguero
Modified: 2026-01-14 18:31 CET (History)
3 users (show)

See Also:
Source RPM: net-snmp-5.9.3-2.1.mga9.src.rpm
CVE: CVE-2025-68615
Status comment:


Attachments

Description Nicolas Salguero 2026-01-12 09:16:35 CET
Reference: https://www.openwall.com/lists/oss-security/2026/01/09/2
Nicolas Salguero 2026-01-12 09:17:38 CET

CVE: (none) => CVE-2025-68615
Flags: (none) => affects_mga9+
Status comment: (none) => Fixed upstream in 5.9.5
Source RPM: (none) => net-snmp-5.9.4-8.mga10.src.rpm, net-snmp-5.9.3-2.1.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 Nicolas Salguero 2026-01-12 09:49:33 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Net-SNMP snmptrapd crash. (CVE-2025-68615)

References:
https://www.openwall.com/lists/oss-security/2026/01/09/2
========================

Updated packages in core/updates_testing:
========================
lib(64)net-snmp-devel-5.9.3-2.2.mga9
lib(64)net-snmp40-5.9.3-2.2.mga9
net-snmp-5.9.3-2.2.mga9
net-snmp-mibs-5.9.3-2.2.mga9
net-snmp-tkmib-5.9.3-2.2.mga9
net-snmp-trapd-5.9.3-2.2.mga9
net-snmp-utils-5.9.3-2.2.mga9
perl-NetSNMP-5.9.3-2.2.mga9
python3-netsnmp-5.9.3-2.2.mga9

from SRPM:
net-snmp-5.9.3-2.2.mga9.src.rpm

Flags: affects_mga9+ => (none)
Status comment: Fixed upstream in 5.9.5 => (none)
Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED
Version: Cauldron => 9
Source RPM: net-snmp-5.9.4-8.mga10.src.rpm, net-snmp-5.9.3-2.1.mga9.src.rpm => net-snmp-5.9.3-2.1.mga9.src.rpm
Whiteboard: MGA9TOO => (none)

Comment 2 Herman Viaene 2026-01-12 15:02:49 CET
MGA9-64 server Plasma Wayland on Compaq H000SB
No installation issues.
Ref bug 33423 for testing
# systemctl start snmpd
# systemctl -l status snmpd
● snmpd.service - Simple Network Management Protocol (SNMP) Daemon.
     Loaded: loaded (/usr/lib/systemd/system/snmpd.service; disabled; preset: disabled)
     Active: active (running) since Mon 2026-01-12 14:55:54 CET; 59s ago
   Main PID: 94599 (snmpd)
      Tasks: 1 (limit: 8805)
     Memory: 3.9M
        CPU: 192ms
     CGroup: /system.slice/snmpd.service
             └─94599 /usr/sbin/snmpd -LS0-4d -f

Jan 12 14:55:53 mach3.hviaene.thuis systemd[1]: Starting snmpd.service...
Jan 12 14:55:54 mach3.hviaene.thuis systemd[1]: Started snmpd.service.

# snmpget -v2c -c public localhost system.sysDescr.0
SNMPv2-MIB::sysDescr.0 = STRING: Linux mach3.hviaene.thuis 6.6.116-server-1.mga9 #1 SMP PREEMPT_DYNAMIC Mon Nov  3 17:28:44 UTC 2025 x86_64

# snmpwalk -v2c -c public localhost
SNMPv2-MIB::sysDescr.0 = STRING: Linux mach3.hviaene.thuis 6.6.116-server-1.mga9 #1 SMP PREEMPT_DYNAMIC Mon Nov  3 17:28:44 UTC 2025 x86_64
SNMPv2-MIB::sysObjectID.0 = OID: NET-SNMP-MIB::netSnmpAgentOIDs.10
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (11500) 0:01:55.00
SNMPv2-MIB::sysContact.0 = STRING: Root <root@localhost> (configure /etc/snmp/snmp.local.conf)
SNMPv2-MIB::sysName.0 = STRING: mach3.hviaene.thuis
SNMPv2-MIB::sysLocation.0 = STRING: Unknown (edit /etc/snmp/snmpd.conf)
SNMPv2-MIB::sysORLastChange.0 = Timeticks: (3) 0:00:00.03
SNMPv2-MIB::sysORID.1 = OID: SNMP-FRAMEWORK-MIB::snmpFrameworkMIBCompliance
SNMPv2-MIB::sysORID.2 = OID: SNMP-MPD-MIB::snmpMPDCompliance
SNMPv2-MIB::sysORID.3 = OID: SNMP-USER-BASED-SM-MIB::usmMIBCompliance
SNMPv2-MIB::sysORID.4 = OID: SNMPv2-MIB::snmpMIB
SNMPv2-MIB::sysORID.5 = OID: SNMP-VIEW-BASED-ACM-MIB::vacmBasicGroup
SNMPv2-MIB::sysORID.6 = OID: TCP-MIB::tcpMIB
SNMPv2-MIB::sysORID.7 = OID: UDP-MIB::udpMIB
SNMPv2-MIB::sysORID.8 = OID: IP-MIB::ip
SNMPv2-MIB::sysORID.9 = OID: SNMP-NOTIFICATION-MIB::snmpNotifyFullCompliance
SNMPv2-MIB::sysORID.10 = OID: NOTIFICATION-LOG-MIB::notificationLogMIB
SNMPv2-MIB::sysORDescr.1 = STRING: The SNMP Management Architecture MIB.
SNMPv2-MIB::sysORDescr.2 = STRING: The MIB for Message Processing and Dispatching.
SNMPv2-MIB::sysORDescr.3 = STRING: The management information definitions for the SNMP User-based Security Model.
SNMPv2-MIB::sysORDescr.4 = STRING: The MIB module for SNMPv2 entities
SNMPv2-MIB::sysORDescr.5 = STRING: View-based Access Control Model for SNMP.
SNMPv2-MIB::sysORDescr.6 = STRING: The MIB module for managing TCP implementations
SNMPv2-MIB::sysORDescr.7 = STRING: The MIB module for managing UDP implementations
SNMPv2-MIB::sysORDescr.8 = STRING: The MIB module for managing IP and ICMP implementations
SNMPv2-MIB::sysORDescr.9 = STRING: The MIB modules for managing SNMP Notification, plus filtering.
SNMPv2-MIB::sysORDescr.10 = STRING: The MIB module for logging SNMP Notifications.
SNMPv2-MIB::sysORUpTime.1 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.2 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.3 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.4 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.5 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.6 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.7 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.8 = Timeticks: (2) 0:00:00.02
SNMPv2-MIB::sysORUpTime.9 = Timeticks: (3) 0:00:00.03
SNMPv2-MIB::sysORUpTime.10 = Timeticks: (3) 0:00:00.03
HOST-RESOURCES-MIB::hrSystemUptime.0 = Timeticks: (359619) 0:59:56.19
HOST-RESOURCES-MIB::hrSystemUptime.0 = No more variables left in this MIB View (It is past the end of the MIB tree)
Looks good.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

katnatek 2026-01-13 02:08:07 CET

Keywords: (none) => advisory

Comment 3 Thomas Andrews 2026-01-14 15:03:41 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 4 Mageia Robot 2026-01-14 18:31:58 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0008.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.