Your message dated Thu, 16 Jul 2026 14:46:02 +0000
with message-id <[email protected]>
and subject line Bug#1140916: fixed in nmap 7.99+dfsg-2
has caused the Debian Bug report #1140916,
regarding nmap: CVE-2026-58058
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1140916: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140916
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: nmap
Version: 7.99+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for nmap.
CVE-2026-58058[0]:
| Nmap through 7.99 does not keep the IPv6 extension-header walk
| within the captured packet in ipv6_get_data_primitive
| (libnetutil/netutil.cc), so the pointer advances past the buffer and
| the remaining-length computation underflows to a large value. A
| scanned target or on-path attacker returning a crafted IPv6 response
| with a truncated extension header can trigger out-of-bounds reads
| and a crash during raw IPv6 scans.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-58058
https://www.cve.org/CVERecord?id=CVE-2026-58058
[1] https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc
[2] https://github.com/nmap/nmap/commit/bb6754e76bb1686315008e1aa1c40202a513fb83
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: nmap
Source-Version: 7.99+dfsg-2
Done: Sven Geuer <[email protected]>
We believe that the bug you reported is fixed in the latest version of
nmap, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sven Geuer <[email protected]> (supplier of updated nmap package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 16 Jul 2026 15:27:22 +0200
Source: nmap
Architecture: source
Version: 7.99+dfsg-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Security Tools <[email protected]>
Changed-By: Sven Geuer <[email protected]>
Closes: 1140916
Changes:
nmap (7.99+dfsg-2) unstable; urgency=medium
.
* Team upload.
* d/p/*:
- Refresh patches.
- Add CVE-2026-58058.patch (Closes: #1140916).
* d/control: Bump debhelper-compat to 14. Consequently, drop all ${*:Depends}
substvar mentionings.
* d/copyright:
- In GPL-2+ license, replace FSF postal address by URL.
- Update packaging copyrights.
* d/u/metadata: Introduce it.
* Add 'Team upload.' to previous changelog stanza.
Checksums-Sha1:
0ac31a19c4d796826867784369a6667d40654cbf 2507 nmap_7.99+dfsg-2.dsc
93013bf9072cbe29d575c73ea217c77ef00e3795 25104 nmap_7.99+dfsg-2.debian.tar.xz
83767389d9a1a8a5923c0ce9b41ec618c757dbef 13420 nmap_7.99+dfsg-2_amd64.buildinfo
Checksums-Sha256:
19a5cc3df1783c33c7b2c2cf9214a3047ebd2fc2685737426c71e0ae2bd6350c 2507
nmap_7.99+dfsg-2.dsc
dfdcd3fde75bba50b50b9621e38088ba82abed3df3d7982d706ca10e93baf33a 25104
nmap_7.99+dfsg-2.debian.tar.xz
5e77bc5d1544bbf22503b0c4b893702f3b2f44952ffe861ef031e5ee8d0e8ad4 13420
nmap_7.99+dfsg-2_amd64.buildinfo
Files:
79c19f477d39853b359aaedc20e58384 2507 net optional nmap_7.99+dfsg-2.dsc
dd4ec0e33c9fe42e30cc3272f02ccc9d 25104 net optional
nmap_7.99+dfsg-2.debian.tar.xz
62d0985f6fcc8edba45575a457b08ff1 13420 net optional
nmap_7.99+dfsg-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJDBAEBCgAtFiEEPfXoqkP8n9/QhvGVrfUO2vit1YUFAmpY3tsPHHNnZUBkZWJp
YW4ub3JnAAoJEK31Dtr4rdWFtvgP/2DdEouMPrN4kLUcbqxezAmBSWxMHi3JvFWC
5wd82rSF5M/9csDer5lhcjVn4kfo0wXtffrYWUOLuA8QPruiYXFy6uiUEOoCLM5K
/BopCcy5hZMjWkGGBI6VCP6/UXSpuZNCTFnPpaGV+qpln3cleE5LYnHCAYNTj+QU
jTBrKKW8OrqTYVvRS8ksVJW2iCtK2FLC2SpuGVJxuQ7GbbT90tgqVNP+8tP8hNkG
n/NyD6AnxZ96z2wqrUZDiil9xR+WKs6knTYuartXb7zFev/SPxWQmAvX7kAng9Qm
abmcHr6wcuiLtwdznM0ICb2X+AGk/KBuUXL8VBJTp9Rj+EqZ6ae/f1ELpz3bCXfp
4+JJKHaEhFguNhJrOku866bHM/4xEPWFMiqdDMcgKFmWPKwcwC6mnPydnFdFOegZ
q+i93aFdevNAzmTI1EC6oVEklYt6bN5RamdGYRXfF8mZNJJVum+Un2mTCBbxs4y3
Gzgvay27yiTUOG4A3ryndEQAcnM8HSOWydaWw8J3FytwCnBlN8IgJqiq3/4J5mgu
0HcXTSKAdKSE2Fysgq6tzIXBKkN1Hb51Hcc12Cm2se71/qsgs1C0qv5FEFMbExZ6
vwHmIdFrsR434Qp0sR1DKlCUMkLamMGFlkn6nPkepLweHDoFovCeQc30LbV6L0TE
VCzaTduI
=e9i8
-----END PGP SIGNATURE-----
pgpZDhwhAhgdF.pgp
Description: PGP signature
--- End Message ---