illumos 名称服务缓存守护进程(nscd)中存在资源未正确释放的问题,导致本地用户可耗尽内核内存。nscd 的 door 服务器过程 switcher()(位于 usr/src/cmd/nscd/nscd_frontend.c)在通过 door 调用传入但未在请求中使用的文件描述符时,未将其关闭。此外,位于 /var/run/name_service_door 的主 nscd door 允许接收来自其区域内任何用户传入的文件描述符。 由于 nscd 还配置了无限制的文件描述符上限,因此任何非特权本地用户(包括
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| illumos | illumos-gate | cb5caa98562cf06753163f558cbcfe30b8f4673a< af810a72c09944e884ec695e8dbf1702a4f424ae |
affected |
| OmniOS | OmniOS | any< r151054 |
affected |
r151058< r151058w |
affected | ||
r151056< r151056aw |
affected | ||
r151054< r151054bw |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| illumos | illumos-gate | cb5caa98562cf06753163f558cbcfe30b8f4673a ~ af810a72c09944e884ec695e8dbf1702a4f424ae | - |
|
| OmniOS | OmniOS | any ~ r151054 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102916 | 6.8 MEDIUM | Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani |
| CVE-2026-104114 | 5.4 MEDIUM | NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae |
| CVE-2026-104115 | 5.4 MEDIUM | Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the |
| CVE-2026-104117 | 1.9 LOW | Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou |
| CVE-2026-104116 | 1.9 LOW | Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum |
No comments yet