CVE-2019-20892

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
25/06/2020
Last modified:
02/09/2022

Description

net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, but might not affect an upstream release.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:* 5.8 (including)
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*