CVE-2022-44792 (https://github.com/net-snmp/net-snmp/issues/474): https://gist.github.com/menglong2234/b7bc13ae1a144f47cc3c95a7ea062428 handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. CVE-2022-44793 (https://github.com/net-snmp/net-snmp/issues/475): https://gist.github.com/menglong2234/d07a65b5028145c9f4e1d1db8c4c202f handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. No patches yet, but upstream seems active.
The two issues are said to be fixed by: https://github.com/net-snmp/net-snmp/commit/be804106fd0771a7d05236cff36e199af077af57