CVE Vulnerabilities

CVE-2019-20892

Double Free

Published: Jun 25, 2020 | Modified: Sep 02, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Net-snmp Net-snmp * 5.8 (including)
Red Hat Enterprise Linux 8 RedHat net-snmp-1:5.8-12.el8_1.1 *
Red Hat Enterprise Linux 8 RedHat net-snmp-1:5.8-12.el8_1.1 *
Net-snmp Ubuntu devel *
Net-snmp Ubuntu focal *
Net-snmp Ubuntu trusty *

Potential Mitigations

References