CVE-2026-58058: Nmap - Integer Underflow in IPv6 Extension Header Parsing
Nmap - Integer Underflow in IPv6 Extension Header Parsing
Other sources
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6getdataprimitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.95-4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58058?
The severity of CVE-2026-58058 is categorized as medium with a score of 6.5.
What is CVE-2026-58058 about?
CVE-2026-58058 addresses an integer underflow vulnerability in Nmap related to IPv6 extension header parsing.
How do I fix CVE-2026-58058?
To remediate CVE-2026-58058, update Nmap to the latest version which addresses the integer underflow issue.
What types of attacks are possible due to CVE-2026-58058?
CVE-2026-58058 could allow a scanned target or an on-path attacker to exploit the integer underflow, potentially leading to further attacks.
Which software is affected by CVE-2026-58058?
CVE-2026-58058 affects Nmap versions up to 7.99.