{"id":"AZL-101742","summary":"CVE-2026-89147 affecting package net-snmp 5.9.5.2-1","details":"Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data, causing the single-threaded snmpd main loop to block indefinitely and suspend all SNMP processing.","modified":"2026-09-18T05:37:08Z","published":"2026-09-11T11:16:58Z","upstream":["CVE-2026-89147"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89147"}],"affected":[{"package":{"name":"net-snmp","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/net-snmp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"5.9.5.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101742.json"}}],"schema_version":"1.9.0"}