CVE Vulnerabilities

CVE-2019-20892

Double Free

Published: Jun 25, 2020 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Net-snmpNet-snmp*5.8 (including)
Red Hat Enterprise Linux 8RedHatnet-snmp-1:5.8-12.el8_1.1*
Red Hat Enterprise Linux 8RedHatnet-snmp-1:5.8-12.el8_1.1*
Net-snmpUbuntudevel*
Net-snmpUbuntuesm-infra/focal*
Net-snmpUbuntufocal*
Net-snmpUbuntutrusty*

Potential Mitigations

References