Re: Net-SNMP 5.9.5. and 5.10.pre2 released to address snmptrapd security vulnerability

Craig Small via Net-snmp-coders <[email protected]> Fri, 2 Jan 2026 19:27:21 +1100
Newsgroups gmane.network.net-snmp.devel
Message-ID <CALy8Cw5g8pSH8EFDTsbdcr5t8WKyCS8Rffx1e388hR7cfqWXMQ@mail.gmail.com>
--===============8874265212168298087==
Content-Type: multipart/alternative; boundary="0000000000001590150647637be1"

--0000000000001590150647637be1
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Fri, 2 Jan 2026, 12:47=E2=80=AFpm Magnus Fromreide, <[email protected]=
e> wrote:

> On Thu, Dec 25, 2025 at 03:23:34PM -0800, Wes Hardaker via Net-snmp-coder=
s
> wrote:
> > Bart Van Assche via Net-snmp-coders
> > <[email protected]> writes:
> >
> > > One possible solution is to modify net-snmp-config such that all -W
> > > flags are filtered out. There may be better solutions.
> >
> > IMHO, the --enable-developer was created for adding options like this
> > and they should never be on anywhere in default builds.  We should
> > remove all warning flags everywhere by default (IMHO, but that's the
> > point of a discussion: I could be alone in my thinking).
>
> I am stronly agreeing and wants to go further - I think all dialect optio=
ns
> should be removed from the net-snmp-config output, so no more
>
> -g
> -fno-strict-aliasing
> -O2
>
> as that should be the the choice of the client program, not us.

I would like that very much. As an example of the issue adding those
options causes, syslog-ng failed to compile with 5.9.5.2 but compiled ok.

What happens is one of the options triggered a compile error in the
syslog-ng code itself because a previous warning was now an error.
So changing the version of net-snmp a program links to caused an error so
it wouldn't compile; but not due to an API change.

 - Craig

--0000000000001590150647637be1
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"auto"><br><br><div class=3D"gmail_quote" dir=
=3D"auto"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, 2 Jan 2026, 12:47=
=E2=80=AFpm Magnus Fromreide, &lt;<a href=3D"mailto:[email protected]" t=
arget=3D"_blank">[email protected]</a>&gt; wrote:<br></div><blockquote c=
lass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;=
padding-left:1ex">On Thu, Dec 25, 2025 at 03:23:34PM -0800, Wes Hardaker vi=
a Net-snmp-coders wrote:<br>
&gt; Bart Van Assche via Net-snmp-coders<br>
&gt; &lt;<a href=3D"mailto:[email protected]" rel=3D"no=
referrer" target=3D"_blank">[email protected]</a>&gt; w=
rites:<br>
&gt; <br>
&gt; &gt; One possible solution is to modify net-snmp-config such that all =
-W<br>
&gt; &gt; flags are filtered out. There may be better solutions.<br>
&gt; <br>
&gt; IMHO, the --enable-developer was created for adding options like this<=
br>
&gt; and they should never be on anywhere in default builds.=C2=A0 We shoul=
d<br>
&gt; remove all warning flags everywhere by default (IMHO, but that&#39;s t=
he<br>
&gt; point of a discussion: I could be alone in my thinking).<br>
<br>
I am stronly agreeing and wants to go further - I think all dialect options=
<br>
should be removed from the net-snmp-config output, so no more<br>
<br>
-g<br>
-fno-strict-aliasing<br>
-O2<br>
<br>
as that should be the the choice of the client program, not us.</blockquote=
></div><div dir=3D"auto">I would like that very much. As an example of the =
issue adding those options causes, syslog-ng failed to compile with 5.9.5.2=
 but compiled ok.</div><div dir=3D"auto"><br></div><div dir=3D"auto">What h=
appens=C2=A0is one of the options triggered a compile error in the syslog-n=
g code itself because a previous warning was now an error.</div><div>So cha=
nging the version of net-snmp a program links to caused an error so it woul=
dn&#39;t compile; but not due to an API change.</div><div><br></div><div>=
=C2=A0- Craig</div></div>
</div>

--0000000000001590150647637be1--


--===============8874265212168298087==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============8874265212168298087==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

--===============8874265212168298087==--