Impact
The vulnerability is caused by a malformed packet containing a zero‑length TCP option that triggers an infinite loop during option parsing. This loop consumes memory until the process runs out of memory, resulting in an application crash. The impact is a denial of service that can be triggered without authentication by any remote attacker who can send packets to the target host.
Affected Systems
Nmap, versions up to and including 7.99, distributed by the Nmap Project. No other vendors or products are mentioned as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. Attackers can exploit this remotely by crafting a TCP packet with a zero‑length option; no special privileges are required, making it straightforward for attackers to crash the application.
OpenCVE Enrichment