Skip to content

[snmp] cve vulnerability Upgrade net-snmp_5.9+dfsg-4+deb11u2 to net-snmp_5.9+dfsg-4+deb11u3#670

Merged
gord1306 merged 1 commit intoedge-core:202311.Xfrom
gord1306:snmpu3
Jan 5, 2026
Merged

[snmp] cve vulnerability Upgrade net-snmp_5.9+dfsg-4+deb11u2 to net-snmp_5.9+dfsg-4+deb11u3#670
gord1306 merged 1 commit intoedge-core:202311.Xfrom
gord1306:snmpu3

Conversation

@gord1306
Copy link
Contributor

@gord1306 gord1306 commented Jan 5, 2026

Why I did it

The deb11u2 has been removed from debain upstream.

According to the https://security-tracker.debian.org/tracker/source-package/net-snmp
it incldues a new patch for CVE-2025-68615

Work item tracking
  • Microsoft ADO (number only):

How I did it

update the version from u2 to u3

How to verify it

verify with sonic-mgmt snmp related test case

Which release branch to backport (provide reason below if selected)

  • 202311

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

…nmp_5.9+dfsg-4+deb11u3

The deb11u2 has been removed from debain upstream.

According to the https://security-tracker.debian.org/tracker/source-package/net-snmp
it incldues a new patch for CVE-2025-68615
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR upgrades the net-snmp package from version 5.9+dfsg-4+deb11u2 to 5.9+dfsg-4+deb11u3 to address a security vulnerability. The upstream Debian package deb11u2 has been removed, making this update necessary.

  • Updates all net-snmp library package versions in the bullseye Docker build environment
  • Updates the SNMPD version reference in the build rules

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
sonic-slave-bullseye/Dockerfile.j2 Updates four libsnmp-related package versions (libsnmp40, libnetsnmptrapd40, libsnmp-base, libsnmp-dev) from deb11u2 to deb11u3
rules/snmpd.mk Updates SNMPD_VERSION_FULL variable from deb11u2 to deb11u3 for bullseye builds

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@gord1306 gord1306 requested a review from chiourung January 5, 2026 02:21
@gord1306 gord1306 merged commit 05d4fbb into edge-core:202311.X Jan 5, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant