Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 28 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans. | |
| Title | Nmap - Integer Underflow in IPv6 Extension Header Parsing | |
| First Time appeared |
Nmap
Nmap nmap |
|
| Weaknesses | CWE-191 | |
| CPEs | cpe:2.3:a:nmap:nmap:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nmap
Nmap nmap |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-28T01:32:59.336Z
Reserved: 2026-06-28T00:58:47.763Z
Link: CVE-2026-58058
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-28T03:30:05Z
Weaknesses