Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104112— Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos 名称服务缓存守护进程(nscd)中存在资源未正确释放的问题,导致本地用户可耗尽内核内存。nscd 的 door 服务器过程 switcher()(位于 usr/src/cmd/nscd/nscd_frontend.c)在通过 door 调用传入但未在请求中使用的文件描述符时,未将其关闭。此外,位于 /var/run/name_service_door 的主 nscd door 允许接收来自其区域内任何用户传入的文件描述符。 由于 nscd 还配置了无限制的文件描述符上限,因此任何非特权本地用户(包括

CVSS 6.8 · Medium

Affected Version Matrix 5

VendorProduct Version RangeStatus
illumos illumos-gate cb5caa98562cf06753163f558cbcfe30b8f4673a< af810a72c09944e884ec695e8dbf1702a4f424ae affected
OmniOS OmniOS any< r151054 affected
r151058< r151058w affected
r151056< r151056aw affected
r151054< r151054bw affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104112

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory
Source: CVE Program / CVE List V5
Vulnerability Description
A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P
Source: CVE Program / CVE List V5
Vulnerability Type
对已超过有效生命周期的资源丧失索引
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate cb5caa98562cf06753163f558cbcfe30b8f4673a ~ af810a72c09944e884ec695e8dbf1702a4f424ae -
OmniOS OmniOS any ~ r151054 -

II. Public POCs for CVE-2026-104112

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104112

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104112 (2)

Vendor Advisories for CVE-2026-104112 (1)

Same Patch Batch · illumos · 2026-10-09 · 6 CVEs total

CVE-2026-102916 6.8 MEDIUM Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani
CVE-2026-104114 5.4 MEDIUM NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae
CVE-2026-104115 5.4 MEDIUM Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the
CVE-2026-104117 1.9 LOW Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou
CVE-2026-104116 1.9 LOW Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum

IV. Related Vulnerabilities

V. Comments for CVE-2026-104112

No comments yet


Leave a comment