CVE-2018-18065: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 17.5% chance of exploitation in the next 30 days.

_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 9.0 only
  • Net-SNMP Net-SNMP: before 5.8 (fixed in 5.8)
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Data Ontap: affected versions not specified
  • Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.5
  • Netapp Hyper Converged Infrastructure: affected versions not specified
  • Netapp Solidfire Element OS: affected versions not specified
  • Netapp Storagegrid Webscale: affected versions not specified
  • Palo Alto Networks PAN-OS: up to and including 7.1.22; from 7.1.23, up to and including 8.0.15; from 8.0.16, up to and including 8.1.6

Published 2018-10-08. Last modified 2026-06-17.