{"id":"AZL-91391","summary":"CVE-2026-58058 affecting package nmap for versions less than 7.95-4","details":"Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.","modified":"2026-08-30T05:26:50Z","published":"2026-06-28T02:16:33Z","upstream":["CVE-2026-58058"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58058"}],"affected":[{"package":{"name":"nmap","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/nmap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.95-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91391.json"}}],"schema_version":"1.9.0"}