#1064968 net-snmp: CVE-2024-26464

Package:
src:net-snmp
Source:
src:net-snmp
Submitter:
Moritz Mühlenhoff
Date:
2024-02-29 04:45:02 UTC
Severity:
normal
Tags:
#1064968#5
Date:
2024-02-28 14:44:56 UTC
From:
To:
Hi,

The following vulnerability was published for net-snmp. This appeared
in the CVE feed, but I doubt that it was actually forwarded upstream.

CVE-2024-26464[0]:
| net-snmp 5.9.4 contains a memory leak vulnerability in /net-
| snmp/apps/snmpvacm.c.

https://github.com/LuMingYinDetect/net-snmp_defects/blob/main/net-snmp_detect_1.md


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-26464
https://www.cve.org/CVERecord?id=CVE-2024-26464

Please adjust the affected versions in the BTS as needed.

#1064968#12
Date:
2024-02-28 20:17:24 UTC
From:
To:
been rejected now.

Reason: This candidate was withdrawn by its CNA. Further investigation
showed that it was not a security issue.

Regards,
Salvatore

#1064968#17
Date:
2024-02-28 20:55:11 UTC
From:
To:
I did wonder myself how it could be a security issue. Wonder if it is one
of those automatic detector things?
Thanks for following up on this.
 - Craig

#1064968#22
Date:
2024-02-29 04:41:25 UTC
From:
To:
Hi,

I guess so. There was in the same feed update for various unrelated
upstream projects CVE assignments similar to this one from the same
reporter.

Regards,
Salvatore