CVE-2025-68615
published 2025-12-23CVE-2025-68615: net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can…
PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
43.26%
98.6th percentile
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | net-snmp | < net-snmp 5.9.3+dfsg-2+deb12u1 (bookworm) | net-snmp 5.9.3+dfsg-2+deb12u1 (bookworm) |
| msrc | azl3_net-snmp_5.9.4-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_net-snmp_5.9.4-1_on_cbl_mariner_2.0 | — | — |
| net-snmp | net-snmp | < 5.9.5 | 5.9.5 |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | — | — |
| net-snmp | net-snmp | >= 0 < 5.9+dfsg-4+deb11u3 | 5.9+dfsg-4+deb11u3 |
| net-snmp | net-snmp | >= 0 < 5.9.3+dfsg-2+deb12u1 | 5.9.3+dfsg-2+deb12u1 |
| net-snmp | net-snmp | >= 0 < 5.9.4+dfsg-2+deb13u1 | 5.9.4+dfsg-2+deb13u1 |
| net-snmp | net-snmp | >= 0 < 5.9.5.2+dfsg-1 | 5.9.5.2+dfsg-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target process: snmptrapd daemon is the vulnerable component; monitor for unexpected crashes or restarts of snmptrapd as a potential indicator of exploitation attempts ↗
- →Attack vector: unauthenticated remote attacker sends a specially crafted SNMP packet to trigger the buffer overflow in snmptrapd; monitor SNMP trap ports (UDP/162) for anomalous or malformed packets from untrusted sources ↗
- →Scope: SNMP ports exposed to public networks significantly increase exploitation risk; audit firewall rules to ensure SNMP ports are not reachable from untrusted networks ↗
- →Mitigation/detection boundary: restrict network traffic to snmptrapd using firewall rules; alert on SNMP trap traffic from unknown or untrusted source IPs ↗
- ·Default Red Hat Enterprise Linux mitigations (SELinux, ASLR, memory protections) reduce exploitability; detections tuned for RCE may have lower fidelity on hardened RHEL systems ↗
- ·Red Hat Enterprise Linux 6 will NOT be patched (marked 'Will not fix'); snmptrapd on RHEL 6 remains permanently vulnerable and should be treated as a high-risk asset ↗
- ·Red Hat OpenShift Container Platform 4 (rhcos) is listed as Affected; container environments running snmptrapd should be assessed separately ↗
- ·Although the primary impact is DoS (daemon crash), memory corruption and arbitrary code execution cannot be ruled out; detection logic should account for both crash-based and potential RCE exploitation paths ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Net-SNMP vulnerability
vendor_ubuntu·2026-01-07
CVE-2025-68615 Net-SNMP vulnerability
Title: Net-SNMP vulnerability
Summary: Net-SNMP could be made to crash if it received specially crafted
input.
Bahae Bahrini discovered that Net-SNMP could be made to write out of
bounds. If a user or an automated system were tricked into opening a
specially crafted input file, a remote attacker could possibly use
this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd
vendor_redhat·2025-12-22·CVSS 9.8
CVE-2025-68615 [CRITICAL] CWE-119 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd
net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
A flaw was found in net-snmp. A remote attacker can trigger a buffer overflow in the snmptrapd daemon by sending a specially crafted SNMP packet, causing the daemon to crash and resulting in a denial of service.
Statement: This issue allows a remote and unauthenticated attacker to trigger a buffer overflow in the snmptrapd daemon by sending a specially crafted SNMP packet, causing it to crash, and resulting in a denial of service.
Howe
Microsoft
Net-SNMP snmptrapd crash
vendor_msrc·2025-12-09·CVSS 9.8
CVE-2025-68615 [CRITICAL] CWE-119 Net-SNMP snmptrapd crash
Net-SNMP snmptrapd crash
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-68615: net-snmp - net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9....
vendor_debian·2025·CVSS 9.8
CVE-2025-68615 [CRITICAL] CVE-2025-68615: net-snmp - net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9....
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Scope: local
bookworm: resolved (fixed in 5.9.3+dfsg-2+deb12u1)
bullseye: resolved (fixed in 5.9+dfsg-4+deb11u3)
forky: resolved (fixed in 5.9.5.2+dfsg-1)
sid: resolved (fixed in 5.9.5.2+dfsg-1)
trixie: resolved (fixed in 5.9.4+dfsg-2+deb13u1)
OSV
CVE-2025-68615: net-snmp is a SNMP application library, tools and daemon
osv·2025-12-23·CVSS 9.8
CVE-2025-68615 [CRITICAL] CVE-2025-68615: net-snmp is a SNMP application library, tools and daemon
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, April 2026 Security Update Review
blogs_qualys·2026-04-22
CVE-2025-6965 Oracle Critical Patch Update, April 2026 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 481 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 139, constituting about 28% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware followed, with 75 and 59 security patches.
376 of the 481 security patches provided by the April Critical Patch Update (about 78%)
Checkpoint
29th December – Threat Intelligence Report
blogs_checkpoint·2025-12-29
CVE-2025-14847 29th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th December, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Romanian Waters, the country’s national water management authority, was hit by a ransomware attack that resulted in nearly 1,000 computer systems across national and regional offices being encrypted. The attack affected geographic information systems, databases, email, web servers, and Windows workstations. Operational
Wiz
CVE-2025-68615 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2025-68615 [CRITICAL] CVE-2025-68615 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68615 :
NixOS vulnerability analysis and mitigation
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Source : NVD
## 9.8
Score
Published December 23, 2025
Severity CRITICAL
CNA Score 9.8
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 45.5
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
net-snmp-libs
net-snmp-devel-32bit
Sources
NVD
AlmaLinux 8 Severity HIGH Has Fix Added at: Jan 21, 2026
Bugzilla
CVE-2025-68615 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd [fedora-42]
bugzilla·2025-12-23·CVSS 9.8
CVE-2025-68615 [CRITICAL] CVE-2025-68615 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd [fedora-42]
CVE-2025-68615 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora
Bugzilla
CVE-2025-68615 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd
bugzilla·2025-12-23·CVSS 9.8
CVE-2025-68615 [CRITICAL] CVE-2025-68615 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd
CVE-2025-68615 net-snmp: buffer overflow via a specially crafted packet can cause a crash in snmptrapd
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:0668 https://access.redhat.com/errata/RHSA-2026:0668
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:0696 https://access.redhat.com/errata/RHSA-2026:0696
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHS
https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gqhttp://www.openwall.com/lists/oss-security/2026/01/09/2https://lists.debian.org/debian-lts-announce/2026/01/msg00000.htmlhttps://www.vicarius.io/vsociety/posts/cve-2025-68615-detection-script-buffer-overflow-vulnerability-affecting-net-snmphttps://www.vicarius.io/vsociety/posts/cve-2025-68615-mitigation-script-buffer-overflow-vulnerability-affecting-net-snmp
2025-12-23
Published