SB2026090290 - Use of uninitialized resource in Mini SNMP daemon
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of uninitialized resource (CVE-ID: N/A)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to uninitialized memory exposure in the SNMP OID encoding and varbind reply generation logic when processing specially crafted SNMP requests with non-minimal OID sub-identifiers. A remote attacker can send a specially crafted request for an absent OID to disclose sensitive information.
On UDP, the leaked data can contain a previous response sent to another client, including echoed community strings. On TCP, a later request on the same connection leaks only that connection\'s previous response.
Remediation
Install update from vendor's website.