OESA-2026-3681
Dashboard / Vulnerabilities / OESA-2026-3681
Summary: nmap security update
Details: Nmap ("Network Mapper") is a free and open source (license) utility for network discovery and security \ auditing. It was designed to rapidly scan large networks, but works fine against single hosts. Security Fix(es): Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.(CVE-2026-72712)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3681, https://nvd.nist.gov/vuln/detail/CVE-2026-72712
Affected packages
Package
Name: nmap
Purl: pkg:rpm/openEuler/nmap&distro=openEuler-24.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
