Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-72712

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.

A flaw was found in Nmap. A remote attacker can exploit this denial of service vulnerability by sending a specially crafted packet that includes a zero-length Transmission Control Protocol (TCP) option. This malformed packet forces the application to enter an infinite loop during packet processing, consuming excessive memory and ultimately causing the Nmap application to crash.

Отчет

Moderate: This denial of service vulnerability in Nmap allows a remote attacker to crash the application by sending a specially crafted TCP packet. The impact is limited to the availability of the Nmap process itself, typically affecting active network scanning operations rather than persistent services.

Меры по смягчению последствий

To mitigate this issue, avoid running Nmap with Network Scripting Engine (NSE) scripts that perform raw packet dissection against untrusted or potentially malicious network targets. This vulnerability is triggered by specially crafted TCP packets when Nmap is actively scanning with such scripts. If Nmap is not required, consider uninstalling the nmap package to eliminate the risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nmapFix deferred
Red Hat Enterprise Linux 6nmapOut of support scope
Red Hat Enterprise Linux 7nmapFix deferred
Red Hat Enterprise Linux 8nmapFix deferred
Red Hat Enterprise Linux 9nmapFix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2514257nmap: Nmap: Denial of Service via zero-length TCP option packet

EPSS

Процентиль: 35%
0.00418
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
17 дней назад

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.

CVSS3: 6.5
nvd
17 дней назад

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.

CVSS3: 6.5
msrc
14 дней назад

Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet

CVSS3: 6.5
debian
17 дней назад

Nmap versions up to and including 7.99 contains a denial of service vu ...

CVSS3: 6.5
github
17 дней назад

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.

EPSS

Процентиль: 35%
0.00418
Низкий

6.5 Medium

CVSS3