← Back to CVE intelligence
CVE intelligence

CVE-2026-58058

Vulnerability intelligence

Published Jun 28, 2026Sources checked Sep 28, 2026
6.5MEDIUMCVSS out of 10
What this means

Review the available evidence

CVE-2026-58058 and is rated Medium severity with a CVSS score of 6.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

Public exploit: Cataloged public exploit.

CISA KEVNot listedBased on the latest collected catalog
EPSS1.5%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-58058?

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.