Synopsis:
nmap security updateSummary:
An update for nmap is now available for openEuler-24.03-LTS-SP4Description:
Nmap ("Network Mapper") is a free and open source (license) utility for network discovery and security \ auditing. It was designed to rapidly scan large networks, but works fine against single hosts.
Security Fix(es):
Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.(CVE-2026-58058)Topic:
An update for nmap is now available for openEuler-24.03-LTS-SP4.
openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.Severity:
MediumAffected Component:
nmap
7.94-10.oe2403sp47.94-10.oe2403sp47.94-10.oe2403sp47.94-10.oe2403sp4Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:LI:NA:L6.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L