#1132997 snmpd: Adding a helpful warning to the SNMPD configuration

Package:
snmpd
Source:
snmpd
Description:
SNMP (Simple Network Management Protocol) agents
Submitter:
Marc Singer
Date:
2026-09-14 08:39:02 UTC
Severity:
normal
Tags:
#1132997#5
Date:
2026-04-08 17:22:49 UTC
From:
To:
In the snmpd configuration file, by default we have this:

# agentaddress: The IP address and port number that the agent will listen on.
#   By default the agent listens to any and all traffic from any
#   interface on the default SNMP port (161).  This allows you to
#   specify which address, interface, transport type and port(s) that you
#   want the agent to listen on.  Multiple definitions of this token
#   are concatenated together (using ':'s).
#   arguments: [transport:]port[@interface/address],...

agentaddress  127.0.0.1,[::1]

# ...

# Read-only access to everyone to the systemonly view
rocommunity  public default -V systemonly
rocommunity6 public default -V systemonly

What this means is that if someone makes the server publicly available
for the sake of monitoring, the server may become available as a DDOS
attack lever as well.

What I am recommending is that we add a stern warning in the default
configuration that changing the listening address and leaving these
public access entries intact may result in creating a hazard on the
Internet if there are no other precautions taken.  Of course, someone
experienced with SNMP would know this implicitly, but this is an easy
detail to miss given that the community 'public' is a discrete feature
of the daemon.

Or, to put it another way, adding access control requiring either a
community string (other than public) or v3 authentication would not
eliminate the open access available via the public community.

#1132997#8
Date:
2026-05-27 10:10:42 UTC
From:
To:
Hello,

Bug #1132997 in net-snmp reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/net-snmp/-/commit/fb3c826250bb23422c30f1850b1fb0747a27560e
------------------------------------------------------------------------
snmpd.conf: Only allow localhost by default

While the listen address only had localhost the community
allowed access from everywhere. Update the community to
only be valid for localhost Closes: #1132997

Also added changelog for Use systemd-sysusers for user creation !17
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1132997

#1132997#15
Date:
2026-09-14 08:38:24 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
net-snmp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1132997@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Craig Small <csmall@debian.org> (supplier of updated net-snmp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Sep 2026 18:18:22 +1000
Source: net-snmp
Architecture: source
Version: 5.9.5.2+dfsg-3
Distribution: unstable
Urgency: medium
Maintainer: Craig Small <csmall@debian.org>
Changed-By: Craig Small <csmall@debian.org>
Closes: 1104474 1106791 1132997 1137756 1147204 1147442
Changes:
 net-snmp (5.9.5.2+dfsg-3) unstable; urgency=medium
 .
   * Use systemd-sysusers for user creation !17
   * snmpd.conf: Only allow localhost by default Closes: #1132997
   * Update build-dep for libmariadb-dev Closes: #1137756
   * Add turkish translation for debconf Closes: #1104474
   * Also update net-snmp-create-user manpage path Closes: #1106791
   * libnl-route is a linux-only dependency Closes: #1147204
   * Added snmptls.1 man page
   * Remove kfreebsd build-deps
   * Set timeout on smux socket Fixes: CVE-2026-89147 Closes: #1147442
Checksums-Sha1:
 aa06f3c8f45f9b58852f690468ffd28eeaec197f 2576 net-snmp_5.9.5.2+dfsg-3.dsc
 2972c6212770c6a7108c3a9613076bbe87a48ff0 71920 net-snmp_5.9.5.2+dfsg-3.debian.tar.xz
 ae2aac84dc07179cac5d97231958e2776ba6963e 10547 net-snmp_5.9.5.2+dfsg-3_amd64.buildinfo
Checksums-Sha256:
 51cef89047f1adc6dee8c02cbfbd7d9a4f12cce441a7572a6bca00ee28f14d13 2576 net-snmp_5.9.5.2+dfsg-3.dsc
 52f9724c9a322d4ac093acd6d7e2cb6a1c2d6f5710a7d5478a0e160092af7eeb 71920 net-snmp_5.9.5.2+dfsg-3.debian.tar.xz
 3124a375068aa73ee6b2f8dff3bf3bda9a6d63a8290fe08335514c5896251d16 10547 net-snmp_5.9.5.2+dfsg-3_amd64.buildinfo
Files:
 cad63c987fe64a00371121027d321679 2576 net optional net-snmp_5.9.5.2+dfsg-3.dsc
 2c2491c15efd946ad8498c91d878d895 71920 net optional net-snmp_5.9.5.2+dfsg-3.debian.tar.xz
 af0467dfea9b36c800d07a61d0c3d96c 10547 net optional net-snmp_5.9.5.2+dfsg-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmqnrsEACgkQAiFmwP88
hOPKfA/8DF20gRX83nV8SzLUbcewpiMmyj8pbgIfxS+pokN+CuUAku6MFU8bIPCN
mzQxdIX/cZlJNfdpO56527UhPKGv+2u2+OYl85o2GdEfD6jcavsePXTetK4dJ6Ee
ykeEwSXDvGDlHWBy1d6V5f+OxxjhGU5M4RED8hb2JrpL2P0KeEuoGHbwB54fVnoE
j75LmQDxt/zPRrwzY4qt0t08r/Y3m4adrIMOs2VPtSezK8kR6Ev1W/T27gj8Qxc1
VU1SyEG3OzngtcLkQsUULrNwGLG521B31nw4/qNF9o4JIhNNw7ePR/9KaqOyCIkp
iqThEfgZrALjkeAWfchbIt0dnN1bb2vploCEy4nY+9ADMf/1ukLvvqtTJKb5AXfP
EFoIrdyZLbd4sSAMCdEwKwrbJ56lfQ2fIqXO+qvUmxXAgDOO55fWaqfggTTLMlL2
ZRKwerrOcGllPHCCsTb0OwAK1UaoQsXDJ3Vx9m0IkWJASyYrZdBd4+eD+N0I1/0w
HMCIv9o7VI+QhB9BAmCOeXdIgjD4DE7WY2ZYlT8kGySwfU2C+00bEdg6ihi8UEVI
wXxWbs+dOmuOOxMaSF0tGVJz2YHPs0RPzVDZsrY5FNE8GTEum9JJvDuvgOlkdk2n
LvxL7n2h+fFNBH9ctYyhL6vNd2u8xIWPTqqfxBOCSrEMZAo/pwU=
=VWDx
-----END PGP SIGNATURE-----