NULL pointer dereference in Net-snmp - CVE-2022-44793
Published: January 10, 2023 / Updated: May 1, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the handle_ipv6IpForwarding() function in agent/mibgroup/ip-mib/ip_scalars.c. A remote attacker can send specially crafted UDP packets to the application and perform a denial of service (DoS) attack.
Affected software
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
openSUSE Leap Micro
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Tanzu Greenplum for Kubernetes
Dell EMC Streaming Data Platform
Enterprise SONiC
RecoverPoint for Virtual Machines
LANTIME Operating System Firmware (LTOS)
SUSE Linux Enterprise Module for Packagehub Subpackages
snmpd (Ubuntu package)
libsnmp30 (Ubuntu package)
snmp (Ubuntu package)
snmp-mibs
libsnmp30-debuginfo-32bit
libsnmp30-32bit
perl-SNMP-debuginfo
perl-SNMP
net-snmp
libsnmp30
net-snmp-devel
net-snmp-debugsource
net-snmp-debuginfo
libsnmp30-debuginfo
libsnmp35 (Ubuntu package)
net-snmp (Red Hat package)
net-snmp-agent-libs
net-snmp-libs
net-snmp-perl
net-snmp-utils
net-snmp-doc
libsnmp40 (Ubuntu package)
python3-net-snmp-debuginfo
libsnmp40-32bit-debuginfo
libsnmp40-32bit
python3-net-snmp
libsnmp40
libsnmp40-debuginfo
net-snmp-devel-32bit
net-snmp-help
net-snmp-gui
SIMATIC MV500
RecoverPoint for VMs
RSA Authentication Manager
IBM Security Verify Governance
How to mitigate CVE-2022-44793
LANTIME Operating System Firmware (LTOS) - update to 7.06.014
snmpd (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.7.3+dfsg-1.8ubuntu3.8, 5.8+dfsg-2ubuntu2.6, 5.9.1+dfsg-1ubuntu2.4, 5.9.3+dfsg-1ubuntu1.2
libsnmp30 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.7.3+dfsg-1.8ubuntu3.8
snmp (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.7.3+dfsg-1.8ubuntu3.8, 5.8+dfsg-2ubuntu2.6, 5.9.1+dfsg-1ubuntu2.4, 5.9.3+dfsg-1ubuntu1.2
Tanzu Greenplum for Kubernetes - update to 1.4.0
Dell EMC Streaming Data Platform - update to 1.7.0
SIMATIC MV500 - update to 3.3.5
Enterprise SONiC - update to 4.1.4
snmp-mibs - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
libsnmp30-debuginfo-32bit - update to 5.7.3-11.6.1
libsnmp30-32bit - update to 5.7.3-11.6.1
perl-SNMP-debuginfo - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
perl-SNMP - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
net-snmp - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
libsnmp30 - update to 5.7.3-11.6.1
net-snmp-devel - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
net-snmp-debugsource - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
net-snmp-debuginfo - addressed in versions 5.7.3-11.6.1, 5.9.3-150300.15.8.1
libsnmp30-debuginfo - update to 5.7.3-11.6.1
libsnmp35 (Ubuntu package) - update to 5.8+dfsg-2ubuntu2.6
net-snmp (Red Hat package) - addressed in versions 5.8-27.el8, 5.9.1-9.el9
net-snmp-agent-libs - update to 5.8-27.0.1
net-snmp - update to 5.8-27.0.1
net-snmp-devel - update to 5.8-27.0.1
net-snmp-libs - update to 5.8-27.0.1
net-snmp-perl - update to 5.8-27.0.1
net-snmp-utils - update to 5.8-27.0.1
net-snmp-doc - update to 5.8-27.0.1
libsnmp40 (Ubuntu package) - addressed in versions 5.9.1+dfsg-1ubuntu2.4, 5.9.3+dfsg-1ubuntu1.2
python3-net-snmp-debuginfo - update to 5.9.3-150300.15.8.1
libsnmp40-32bit-debuginfo - update to 5.9.3-150300.15.8.1
libsnmp40-32bit - update to 5.9.3-150300.15.8.1
python3-net-snmp - update to 5.9.3-150300.15.8.1
libsnmp40 - update to 5.9.3-150300.15.8.1
libsnmp40-debuginfo - update to 5.9.3-150300.15.8.1
net-snmp-devel-32bit - update to 5.9.3-150300.15.8.1
net-snmp-help - update to 5.9-8
net-snmp-devel - update to 5.9-8
net-snmp-debuginfo - update to 5.9-8
net-snmp-debugsource - update to 5.9-8
net-snmp-perl - update to 5.9-8
net-snmp-libs - update to 5.9-8
net-snmp-gui - update to 5.9-8
python3-net-snmp - update to 5.9-8
net-snmp - update to 5.9-8
RecoverPoint for VMs - update to 6.0.SP1.P1
RSA Authentication Manager - update to 8.7 Patch 3
IBM Security Verify Governance - update to 10.0.2.0.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Net-snmp
- Ubuntu update for net-snmp
- SUSE update for net-snmp
- SUSE update for net-snmp
- Ubuntu update for net-snmp
- Tanzu Greenplum for Kubernetes update for Net-SNMP
- Red Hat Enterprise Linux 9 update for net-snmp
- Red Hat Enterprise Linux 8 update for net-snmp
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Dell Streaming Data Platform
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Siemens SIMATIC MV500
- openEuler update for net-snmp
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Anolis OS update for net-snmp
- RSA Authentication Manager update for third-party components
- Meinberg LANTIME firmware update for third-party components (May 2023)
- Dell RecoverPoint for Virtual Machines update for third-party components