Stack-based buffer overflow in Net-snmp - CVE-2025-68615
Published: December 26, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the SnmpTrapd service. A remote unauthenticated attacker can send specially crafted input to port 162/UDP, trigger a stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Juniper Junos Space
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP6
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Oracle Communications Operations Monitor
Total Storage Service Console (TSSC) / TS4500 IMC
Oracle Communications EAGLE LNP Application Processor
Oracle Communications Policy Management
Oracle Communications EAGLE Application Processor
Oracle Tuxedo
Telco Service Orchestrator
Communications Unified Assurance
Oracle Communications Instant Messaging Server
Oracle Communications EAGLE
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
net-snmp (Ubuntu package)
net-snmp-sysvinit
net-snmp
net-snmp-agent-libs
net-snmp-devel
net-snmp-gui
net-snmp-libs
net-snmp-perl
net-snmp-python
net-snmp-utils
net-snmp (Red Hat package)
libsnmp30-32bit-debuginfo
libsnmp30-32bit
net-snmp-debuginfo
net-snmp-debugsource
libsnmp30
libsnmp30-debuginfo
net-snmp-doc
net-snmp-help
python3-net-snmp
net-snmp (Debian package)
libsnmp40
perl-SNMP-debuginfo
snmp-mibs
perl-SNMP
libsnmp40-debuginfo
libsnmp40-debuginfo-32bit
libsnmp40-32bit
net-snmp-devel-32bit
libsnmp40-32bit-debuginfo
python2-net-snmp-debuginfo
python2-net-snmp
python3-net-snmp-debuginfo
net-snmp-devel-64bit
libsnmp40-64bit-debuginfo
libsnmp40-64bit
Oracle Communications LSMS
IBM Cloud Object Storage Systems
IBM Power Hardware Management Console (HMC)
How to mitigate CVE-2025-68615
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF05
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69
Telco Service Orchestrator - update to 4.2.12
net-snmp (Ubuntu package) - addressed in versions 5.7.2~dfsg-8.1ubuntu3.3+esm4, 5.7.3+dfsg-1.8ubuntu3.8+esm1, 5.7.3+dfsg-1ubuntu4.6+esm2, 5.8+dfsg-2ubuntu2.9+esm2, 5.9.1+dfsg-1ubuntu2.9, 5.9.4+dfsg-2ubuntu2.1, 5.9.4+dfsg-1.1ubuntu3.2, 5.9.4+dfsg-1.1ubuntu7.1
net-snmp-sysvinit - update to 5.7.2-49
net-snmp - addressed in versions 5.7.2-49, 5.8-33.0.1, 5.9.4-2
net-snmp-agent-libs - addressed in versions 5.7.2-49, 5.8-33.0.1, 5.9.4-2
net-snmp-devel - addressed in versions 5.7.2-49, 5.8-33.0.1, 5.9.4-2
net-snmp-gui - addressed in versions 5.7.2-49, 5.9.4-2
net-snmp-libs - addressed in versions 5.7.2-49, 5.8-33.0.1, 5.9.4-2
net-snmp-perl - addressed in versions 5.7.2-49, 5.8-33.0.1, 5.9.4-2
net-snmp-python - update to 5.7.2-49
net-snmp-utils - addressed in versions 5.7.2-49, 5.8-33.0.1, 5.9.4-2
net-snmp (Red Hat package) - addressed in versions 5.7.2-49.el7_9.5, 5.8-14.el8_2.6, 5.8-20.el8_4.3, 5.8-25.el8_6.3, 5.8-27.el8_8.3, 5.8-33.el8_10, 5.9.1-7.el9_0.3, 5.9.1-11.el9_2.3, 5.9.1-13.el9_4.4, 5.9.1-17.el9_6.1, 5.9.1-17.el9_7.1, 5.9.4-15.el10_0.2, 5.9.4-15.el10_1.2
libsnmp30-32bit-debuginfo - update to 5.7.3-150100.10.15.1
libsnmp30-32bit - update to 5.7.3-150100.10.15.1
net-snmp-debuginfo - addressed in versions 5.7.3-150100.10.15.1, 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
net-snmp-debugsource - addressed in versions 5.7.3-150100.10.15.1, 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
libsnmp30 - update to 5.7.3-150100.10.15.1
libsnmp30-debuginfo - update to 5.7.3-150100.10.15.1
net-snmp-doc - update to 5.8-33.0.1
net-snmp-devel - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp-debuginfo - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp-debugsource - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp-gui - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp-libs - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp-perl - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp-help - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
python3-net-snmp - addressed in versions 5.9.1-8, 5.9.3-5, 5.9-10
net-snmp (Debian package) - addressed in versions 5.9.3+dfsg-2+deb12u1, 5.9.4+dfsg-2+deb13u1
python3-net-snmp - update to 5.9.4-2
libsnmp40 - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
net-snmp - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
perl-SNMP-debuginfo - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
snmp-mibs - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
net-snmp-devel - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
perl-SNMP - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
libsnmp40-debuginfo - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
libsnmp40-debuginfo-32bit - update to 5.9.4-14.11.1
libsnmp40-32bit - addressed in versions 5.9.4-14.11.1, 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
net-snmp-devel-32bit - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
libsnmp40-32bit-debuginfo - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
python3-net-snmp - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
python2-net-snmp-debuginfo - update to 5.9.4-150300.15.21.1
python2-net-snmp - update to 5.9.4-150300.15.21.1
python3-net-snmp-debuginfo - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
net-snmp-devel-64bit - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
libsnmp40-64bit-debuginfo - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
libsnmp40-64bit - addressed in versions 5.9.4-150300.15.21.1, 5.9.4-150600.24.10.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1063.2, 11.1.1111.5
Juniper Junos Space - update to 26.1R1 Patch V1
External References
Related Security Bulletins
- Remote code execution in Net-SNMP
- Ubuntu update for net-snmp
- Debian update for net-snmp
- Red Hat Enterprise Linux 10 update for net-snmp
- HPE Telco Service Orchestrator update for Net-snmp
- openEuler 22.03 LTS SP4 update for net-snmp
- openEuler 22.03 LTS SP3 update for net-snmp
- openEuler 24.03 LTS SP3 update for net-snmp
- openEuler 24.03 LTS SP2 update for net-snmp
- openEuler 24.03 LTS SP1 update for net-snmp
- openEuler 24.03 LTS update for net-snmp
- Red Hat Enterprise Linux 10 update for net-snmp
- Red Hat Enterprise Linux 9 update for net-snmp
- Red Hat Enterprise Linux 8 update for net-snmp
- Red Hat Enterprise Linux 8 update for net-snmp
- Red Hat Enterprise Linux 8 update for net-snmp
- Red Hat Enterprise Linux 8 update for net-snmp
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for net-snmp
- Red Hat Enterprise Linux 9 update for net-snmp
- Red Hat Enterprise Linux 8 update for net-snmp
- Red Hat Enterprise Linux 9 update for net-snmp
- Red Hat Enterprise Linux 9 update for net-snmp
- Red Hat Enterprise Linux 9 update for net-snmp
- SUSE update for net-snmp
- SUSE update for net-snmp
- SUSE update for net-snmp
- SUSE update for net-snmp
- Anolis OS update for net-snmp
- openEuler 20.03 LTS SP4 update for net-snmp
- Anolis OS update for net-snmp
- Anolis OS update for net-snmp
- Multiple vulnerabilities in IBM Total Storage Service Console (TSSC) / TS4500 IMC
- Multiple vulnerabilities in IBM QRadar SIEM
- SUSE update for net-snmp
- IBM Power Hardware Management Console (HMC) update for net-snmp
- Multiple vulnerabilities in Oracle Communications Operations Monitor
- Stack-based buffer overflow in Oracle Communications EAGLE
- Multiple vulnerabilities in Oracle Communications EAGLE LNP Application Processor
- Multiple vulnerabilities in Oracle Communications EAGLE Application Processor
- Multiple vulnerabilities in Oracle Communications LSMS
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Communications Unified Assurance
- Stack-based buffer overflow in Oracle Tuxedo
- Multiple vulnerabilities in IBM Cloud Object System
- Multiple vulnerabilities in Junos Space