CVE-2026-72712

NameCVE-2026-72712
DescriptionNmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nmap (PTS)bullseye7.91+dfsg1+really7.80+dfsg1-2vulnerable
bookworm7.93+dfsg1-1vulnerable
trixie7.95+dfsg-3vulnerable
forky, sid7.99+dfsg-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nmapsource(unstable)(unfixed)unimportant

Notes

https://github.com/nmap/nmap/issues/3368
Fixed by: https://github.com/nmap/nmap/commit/7ef4ee030a0023fe22616387a000032e1a678b6a (v7.991)
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems