Your message dated Mon, 14 Sep 2026 08:38:24 +0000
with message-id <[email protected]>
and subject line Bug#1132997: fixed in net-snmp 5.9.5.2+dfsg-3
has caused the Debian Bug report #1132997,
regarding snmpd: Adding a helpful warning to the SNMPD configuration
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1132997: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1132997
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: snmpd
Version: 5.9.3+dfsg-2
Severity: wishlist
In the snmpd configuration file, by default we have this:
# agentaddress: The IP address and port number that the agent will listen on.
# By default the agent listens to any and all traffic from any
# interface on the default SNMP port (161). This allows you to
# specify which address, interface, transport type and port(s) that you
# want the agent to listen on. Multiple definitions of this token
# are concatenated together (using ':'s).
# arguments: [transport:]port[@interface/address],...
agentaddress 127.0.0.1,[::1]
# ...
# Read-only access to everyone to the systemonly view
rocommunity public default -V systemonly
rocommunity6 public default -V systemonly
What this means is that if someone makes the server publicly available
for the sake of monitoring, the server may become available as a DDOS
attack lever as well.
What I am recommending is that we add a stern warning in the default
configuration that changing the listening address and leaving these
public access entries intact may result in creating a hazard on the
Internet if there are no other precautions taken. Of course, someone
experienced with SNMP would know this implicitly, but this is an easy
detail to miss given that the community 'public' is a discrete feature
of the daemon.
Or, to put it another way, adding access control requiring either a
community string (other than public) or v3 authentication would not
eliminate the open access available via the public community.
-- System Information:
Debian Release: 13.3
APT prefers stable
APT policy: (990, 'stable'), (500, 'stable-updates'), (500,
'stable-security'), (500, 'oldstable-updates'), (500, 'oldstable-security'),
(500, 'oldoldstable'), (500, 'unstable'), (500, 'oldstable'), (1,
'experimental')
Architecture: amd64 (x86_64)
Kernel: Linux 6.1.0-32-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages snmpd depends on:
ii adduser 3.134
ii debconf [debconf-2.0] 1.5.82
ii init-system-helpers 1.69~deb13u1
ii libc6 2.41-12+deb13u1
ii libsnmp-base 5.9.3+dfsg-2
ii libsnmp40 5.9.3+dfsg-2
ii lsb-base 11.6
ii sysvinit-utils [lsb-base] 3.06-4
snmpd recommends no packages.
Versions of packages snmpd suggests:
pn snmptrapd <none>
-- Configuration Files:
/etc/snmp/snmpd.conf changed [not included]
-- debconf information excluded
--- End Message ---
--- Begin Message ---
Source: net-snmp
Source-Version: 5.9.5.2+dfsg-3
Done: Craig Small <[email protected]>
We believe that the bug you reported is fixed in the latest version of
net-snmp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Craig Small <[email protected]> (supplier of updated net-snmp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 14 Sep 2026 18:18:22 +1000
Source: net-snmp
Architecture: source
Version: 5.9.5.2+dfsg-3
Distribution: unstable
Urgency: medium
Maintainer: Craig Small <[email protected]>
Changed-By: Craig Small <[email protected]>
Closes: 1104474 1106791 1132997 1137756 1147204 1147442
Changes:
net-snmp (5.9.5.2+dfsg-3) unstable; urgency=medium
.
* Use systemd-sysusers for user creation !17
* snmpd.conf: Only allow localhost by default Closes: #1132997
* Update build-dep for libmariadb-dev Closes: #1137756
* Add turkish translation for debconf Closes: #1104474
* Also update net-snmp-create-user manpage path Closes: #1106791
* libnl-route is a linux-only dependency Closes: #1147204
* Added snmptls.1 man page
* Remove kfreebsd build-deps
* Set timeout on smux socket Fixes: CVE-2026-89147 Closes: #1147442
Checksums-Sha1:
aa06f3c8f45f9b58852f690468ffd28eeaec197f 2576 net-snmp_5.9.5.2+dfsg-3.dsc
2972c6212770c6a7108c3a9613076bbe87a48ff0 71920
net-snmp_5.9.5.2+dfsg-3.debian.tar.xz
ae2aac84dc07179cac5d97231958e2776ba6963e 10547
net-snmp_5.9.5.2+dfsg-3_amd64.buildinfo
Checksums-Sha256:
51cef89047f1adc6dee8c02cbfbd7d9a4f12cce441a7572a6bca00ee28f14d13 2576
net-snmp_5.9.5.2+dfsg-3.dsc
52f9724c9a322d4ac093acd6d7e2cb6a1c2d6f5710a7d5478a0e160092af7eeb 71920
net-snmp_5.9.5.2+dfsg-3.debian.tar.xz
3124a375068aa73ee6b2f8dff3bf3bda9a6d63a8290fe08335514c5896251d16 10547
net-snmp_5.9.5.2+dfsg-3_amd64.buildinfo
Files:
cad63c987fe64a00371121027d321679 2576 net optional net-snmp_5.9.5.2+dfsg-3.dsc
2c2491c15efd946ad8498c91d878d895 71920 net optional
net-snmp_5.9.5.2+dfsg-3.debian.tar.xz
af0467dfea9b36c800d07a61d0c3d96c 10547 net optional
net-snmp_5.9.5.2+dfsg-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXT3w9TizJ8CqeneiAiFmwP88hOMFAmqnrsEACgkQAiFmwP88
hOPKfA/8DF20gRX83nV8SzLUbcewpiMmyj8pbgIfxS+pokN+CuUAku6MFU8bIPCN
mzQxdIX/cZlJNfdpO56527UhPKGv+2u2+OYl85o2GdEfD6jcavsePXTetK4dJ6Ee
ykeEwSXDvGDlHWBy1d6V5f+OxxjhGU5M4RED8hb2JrpL2P0KeEuoGHbwB54fVnoE
j75LmQDxt/zPRrwzY4qt0t08r/Y3m4adrIMOs2VPtSezK8kR6Ev1W/T27gj8Qxc1
VU1SyEG3OzngtcLkQsUULrNwGLG521B31nw4/qNF9o4JIhNNw7ePR/9KaqOyCIkp
iqThEfgZrALjkeAWfchbIt0dnN1bb2vploCEy4nY+9ADMf/1ukLvvqtTJKb5AXfP
EFoIrdyZLbd4sSAMCdEwKwrbJ56lfQ2fIqXO+qvUmxXAgDOO55fWaqfggTTLMlL2
ZRKwerrOcGllPHCCsTb0OwAK1UaoQsXDJ3Vx9m0IkWJASyYrZdBd4+eD+N0I1/0w
HMCIv9o7VI+QhB9BAmCOeXdIgjD4DE7WY2ZYlT8kGySwfU2C+00bEdg6ihi8UEVI
wXxWbs+dOmuOOxMaSF0tGVJz2YHPs0RPzVDZsrY5FNE8GTEum9JJvDuvgOlkdk2n
LvxL7n2h+fFNBH9ctYyhL6vNd2u8xIWPTqqfxBOCSrEMZAo/pwU=
=VWDx
-----END PGP SIGNATURE-----
pgp09hLKjcACa.pgp
Description: PGP signature
--- End Message ---