CVE-2019-20892 describes a double free vulnerability in net-snmp versions prior to 5.8.1.pre1, specifically within the usm_free_usmStateReference function, triggered by a crafted SNMPv3 GetBulk request. This flaw primarily impacts net-snmp packages distributed by various Linux distributions, as well as Oracle net_snmp and ZFS Storage Appliance Kit. Rated with a CVSS v3.1 score of 6.5 (Medium), it presents a network-based attack vector with low attack complexity, requiring low privileges, and could lead to high availability impact (denial of service). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.8CPE matchmatch criteria | cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:* | ||
8.8CPE matchmatch criteria | cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-20892
Aug 11, 2020net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions but might not affect an upstream release.
Jun 9, 2020net-snmp: double free in usm_free_usmStateReference function in snmplib/snmpusm.c via an SNMPv3 GetBulk request
Jan 2, 2020