diff --git a/net-snmp-5.8-callback-fix.patch b/net-snmp-5.8-callback-fix.patch new file mode 100644 index 0000000..d82a41f --- /dev/null +++ b/net-snmp-5.8-callback-fix.patch @@ -0,0 +1,32 @@ +diff -urNp a/snmplib/callback.c b/snmplib/callback.c +--- a/snmplib/callback.c 2025-08-13 15:21:25.507544080 +0200 ++++ b/snmplib/callback.c 2025-08-13 15:25:01.973092935 +0200 +@@ -346,13 +346,17 @@ snmp_call_callbacks(int major, int minor + /* + * for each registered callback of type major and minor + */ +- for (scp = thecallbacks[major][minor]; scp != NULL; scp = scp->next) { ++ scp = thecallbacks[major][minor]; ++ while (scp != NULL) { ++ struct snmp_gen_callback *scp_next = scp->next; + + /* + * skip unregistered callbacks + */ +- if(NULL == scp->sc_callback) ++ if(NULL == scp->sc_callback) { ++ scp = scp_next; + continue; ++ } + + DEBUGMSGTL(("callback", "calling a callback for maj=%d min=%d\n", + major, minor)); +@@ -363,6 +367,8 @@ snmp_call_callbacks(int major, int minor + (*(scp->sc_callback)) (major, minor, caller_arg, + scp->sc_client_arg); + count++; ++ ++ scp = scp_next; + } + + DEBUGMSGTL(("callback", diff --git a/net-snmp-5.9.4-revert-n-snmptrapd-log.patch b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch new file mode 100644 index 0000000..e49d571 --- /dev/null +++ b/net-snmp-5.9.4-revert-n-snmptrapd-log.patch @@ -0,0 +1,12 @@ +diff -urNp a/apps/snmptrapd_log.c b/apps/snmptrapd_log.c +--- a/apps/snmptrapd_log.c 2025-09-03 15:15:12.510914175 +0200 ++++ b/apps/snmptrapd_log.c 2025-09-03 15:15:40.804731480 +0200 +@@ -590,7 +590,7 @@ realloc_handle_time_fmt(u_char ** buf, s + static + void convert_agent_addr(struct in_addr agent_addr, char *name, size_t size) + { +- const int numeric = !netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID, ++ const int numeric = netsnmp_ds_get_boolean(NETSNMP_DS_APPLICATION_ID, + NETSNMP_DS_APP_NUMERIC_IP); + struct sockaddr_in sin; + diff --git a/net-snmp-tmpfilesd.conf b/net-snmp-tmpfilesd.conf new file mode 100644 index 0000000..7130bce --- /dev/null +++ b/net-snmp-tmpfilesd.conf @@ -0,0 +1 @@ +d /var/lib/net-snmp 0755 root root - diff --git a/net-snmp.spec b/net-snmp.spec index 2ad5d30..ee0c7be 100644 --- a/net-snmp.spec +++ b/net-snmp.spec @@ -10,7 +10,7 @@ Summary: A collection of SNMP protocol tools and libraries Name: net-snmp Version: 5.9.4 -Release: 15%{?dist}.2 +Release: 19%{?dist} Epoch: 1 License: MIT-CMU and BSD-3-Clause and MIT and OpenSSL @@ -26,6 +26,7 @@ Source7: net-snmp-tmpfs.conf Source8: snmpd.service Source9: snmptrapd.service Source10: IETF-MIB-LICENSE.txt +Source11: net-snmp-tmpfilesd.conf Patch1: net-snmp-5.9-pie.patch Patch2: net-snmp-5.9-dir-fix.patch @@ -54,7 +55,9 @@ Patch24: net-snmp-5.9.4-test-fix.patch Patch25: net-snmp-5.9.4-kernel-6.7.patch Patch26: net-snmp-5.9.4-remove-mail-sender.patch Patch27: net-snmp-5.9.4-tls.patch -Patch28: net-snmp-5.9.4-oob-access.patch +Patch28: net-snmp-5.9.4-revert-n-snmptrapd-log.patch +Patch29: net-snmp-5.8-callback-fix.patch +Patch30: net-snmp-5.9.4-oob-access.patch # Modern RPM API means at least EL6 Patch101: net-snmp-5.8-modern-rpm-api.patch @@ -68,7 +71,7 @@ Requires: %{name}-agent-libs%{?_isa} = %{epoch}:%{version}-%{release} # is not valid. We can use %%post because this particular %%triggerun script # should fire just after this package is installed. %{?systemd_requires} -BuildRequires: make +BuildRequires: make BuildRequires: systemd BuildRequires: gcc BuildRequires: openssl-devel, bzip2-devel, elfutils-devel @@ -95,6 +98,8 @@ BuildRequires: perl(warnings) BuildRequires: lm_sensors-devel >= 3 %endif BuildRequires: autoconf, automake +# For _tmpfilesdir macro +BuildRequires: systemd-rpm-macros %description SNMP (Simple Network Management Protocol) is a protocol used for @@ -248,7 +253,9 @@ cp %{SOURCE10} . %patch 25 -p1 -b .kernel-fix %patch 26 -p1 -b .remove-mail-sender %patch 27 -p1 -b .tls -%patch 28 -p1 -b .oob-access +%patch 28 -p1 -b .revert-n-snmptrapd-log +%patch 29 -p1 -b .callback-fix +%patch 30 -p1 -b .oob-access %patch 101 -p1 -b .modern-rpm-api %patch 102 -p1 @@ -347,6 +354,7 @@ install -m 644 %SOURCE4 %{buildroot}%{_sysconfdir}/snmp/snmptrapd.conf install -d %{buildroot}%{_sysconfdir}/sysconfig install -m 644 %SOURCE5 %{buildroot}%{_sysconfdir}/sysconfig/snmpd install -m 644 %SOURCE6 %{buildroot}%{_sysconfdir}/sysconfig/snmptrapd +install -p -D -m 644 %SOURCE11 %{buildroot}%{_tmpfilesdir}/%{name}.conf # prepare /var/lib/net-snmp install -d %{buildroot}%{_localstatedir}/lib/net-snmp @@ -442,6 +450,7 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_bindir}/snmpconf %{_bindir}/net-snmp-create-v3-user %{_sbindir}/* +%{_tmpfilesdir}/%{name}.conf %attr(0644,root,root) %{_mandir}/man[58]/snmp*d* %attr(0644,root,root) %{_mandir}/man5/snmp_config.5.gz %attr(0644,root,root) %{_mandir}/man5/variables* @@ -519,11 +528,18 @@ LD_LIBRARY_PATH=%{buildroot}/%{_libdir} make test %{_libdir}/libnetsnmptrapd*.so.%{soname}* %changelog -* Tue Jan 13 2026 Josef Ridky - 1:5.9.4-15.2 -- fix out of bound access (RHEL-137497) +* Mon Feb 02 2026 Josef Ridky - 1:5.9.4-19 +- fix creation of /var/lib/net-snmp in image mode (RHEL-132654) -* Mon Sep 08 2025 Josef Ridky - 1:5.9.4-15.1 -- enable PQC (RHEL-112338) +* Tue Jan 13 2026 Josef Ridky - 1:5.9.4-18 +- fix out-of-bound access issue (RHEL-137498) + +* Mon Nov 10 2025 Josef Ridky - 1:5.9.4-17 +- fix use after free issue (RHEL-121405) + +* Wed Sep 03 2025 Josef Ridky - 1:5.9.4-16 +- Enable PQC in net-snmp (RHEL-93087) +- Fix inverted use of -n in snmptrapd_log.c (RHEL-110514) * Fri Mar 21 2025 Josef Ridky - 1:5.9.4-15 - Resolves: RHEL-81121