#1140916 nmap: CVE-2026-58058

Package:
src:nmap
Source:
src:nmap
Submitter:
Salvatore Bonaccorso
Date:
2026-07-16 14:53:02 UTC
Severity:
normal
Tags:
#1140916#5
Date:
2026-06-28 11:49:11 UTC
From:
To:
Hi,

The following vulnerability was published for nmap.

CVE-2026-58058[0]:
| Nmap through 7.99 does not keep the IPv6 extension-header walk
| within the captured packet in ipv6_get_data_primitive
| (libnetutil/netutil.cc), so the pointer advances past the buffer and
| the remaining-length computation underflows to a large value. A
| scanned target or on-path attacker returning a crafted IPv6 response
| with a truncated extension header can trigger out-of-bounds reads
| and a crash during raw IPv6 scans.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-58058
https://www.cve.org/CVERecord?id=CVE-2026-58058
[1] https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc
[2] https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140916#10
Date:
2026-07-16 14:46:02 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nmap, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140916@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sven Geuer <sge@debian.org> (supplier of updated nmap package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 16 Jul 2026 15:27:22 +0200
Source: nmap
Architecture: source
Version: 7.99+dfsg-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Sven Geuer <sge@debian.org>
Closes: 1140916
Changes:
 nmap (7.99+dfsg-2) unstable; urgency=medium
 .
   * Team upload.
   * d/p/*:
     - Refresh patches.
     - Add CVE-2026-58058.patch (Closes: #1140916).
   * d/control: Bump debhelper-compat to 14. Consequently, drop all ${*:Depends}
     substvar mentionings.
   * d/copyright:
     - In GPL-2+ license, replace FSF postal address by URL.
     - Update packaging copyrights.
   * d/u/metadata: Introduce it.
   * Add 'Team upload.' to previous changelog stanza.
Checksums-Sha1:
 0ac31a19c4d796826867784369a6667d40654cbf 2507 nmap_7.99+dfsg-2.dsc
 93013bf9072cbe29d575c73ea217c77ef00e3795 25104 nmap_7.99+dfsg-2.debian.tar.xz
 83767389d9a1a8a5923c0ce9b41ec618c757dbef 13420 nmap_7.99+dfsg-2_amd64.buildinfo
Checksums-Sha256:
 19a5cc3df1783c33c7b2c2cf9214a3047ebd2fc2685737426c71e0ae2bd6350c 2507 nmap_7.99+dfsg-2.dsc
 dfdcd3fde75bba50b50b9621e38088ba82abed3df3d7982d706ca10e93baf33a 25104 nmap_7.99+dfsg-2.debian.tar.xz
 5e77bc5d1544bbf22503b0c4b893702f3b2f44952ffe861ef031e5ee8d0e8ad4 13420 nmap_7.99+dfsg-2_amd64.buildinfo
Files:
 79c19f477d39853b359aaedc20e58384 2507 net optional nmap_7.99+dfsg-2.dsc
 dd4ec0e33c9fe42e30cc3272f02ccc9d 25104 net optional nmap_7.99+dfsg-2.debian.tar.xz
 62d0985f6fcc8edba45575a457b08ff1 13420 net optional nmap_7.99+dfsg-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEEPfXoqkP8n9/QhvGVrfUO2vit1YUFAmpY3tsPHHNnZUBkZWJp
YW4ub3JnAAoJEK31Dtr4rdWFtvgP/2DdEouMPrN4kLUcbqxezAmBSWxMHi3JvFWC
5wd82rSF5M/9csDer5lhcjVn4kfo0wXtffrYWUOLuA8QPruiYXFy6uiUEOoCLM5K
/BopCcy5hZMjWkGGBI6VCP6/UXSpuZNCTFnPpaGV+qpln3cleE5LYnHCAYNTj+QU
jTBrKKW8OrqTYVvRS8ksVJW2iCtK2FLC2SpuGVJxuQ7GbbT90tgqVNP+8tP8hNkG
n/NyD6AnxZ96z2wqrUZDiil9xR+WKs6knTYuartXb7zFev/SPxWQmAvX7kAng9Qm
abmcHr6wcuiLtwdznM0ICb2X+AGk/KBuUXL8VBJTp9Rj+EqZ6ae/f1ELpz3bCXfp
4+JJKHaEhFguNhJrOku866bHM/4xEPWFMiqdDMcgKFmWPKwcwC6mnPydnFdFOegZ
q+i93aFdevNAzmTI1EC6oVEklYt6bN5RamdGYRXfF8mZNJJVum+Un2mTCBbxs4y3
Gzgvay27yiTUOG4A3ryndEQAcnM8HSOWydaWw8J3FytwCnBlN8IgJqiq3/4J5mgu
0HcXTSKAdKSE2Fysgq6tzIXBKkN1Hb51Hcc12Cm2se71/qsgs1C0qv5FEFMbExZ6
vwHmIdFrsR434Qp0sR1DKlCUMkLamMGFlkn6nPkepLweHDoFovCeQc30LbV6L0TE
VCzaTduI
=e9i8
-----END PGP SIGNATURE-----

#1140916#13
Date:
2026-07-16 14:46:49 UTC
From:
To:
Hello,

Bug #1140916 in nmap reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/pkg-security-team/nmap/-/commit/8b7c6b8f819bc758e9b69c87dcbd4147cee8cceb
------------------------------------------------------------------------
d/p/*: Add CVE-2026-58058.patch.

Closes: #1140916
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1140916