Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104113— Double free in OmniOS and SmartOS ipmgmtd allows local users to crash the daemon

Quick assessment

Affected
OmniOS OmniOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OmniOS 和 SmartOS 的 IP 管理守护进程(ipmgmtd)中存在一个双重释放漏洞,允许本地用户使该守护进程崩溃。当处理修改接口配置的门(door)请求授权时,usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c 中的 ipmgmt_handler() 函数在读取用户 ID 后立即调用 ucred_free() 释放调用者的凭证,并在授权检查失败的错误路径上再次释放同一凭证。没有持有 solaris.network.interface.config 授权的无特权

CVSS 5.4 · Medium

Affected Version Matrix 4

VendorProduct Version RangeStatus
OmniOS OmniOS r151020< r151054 affected
r151058< r151058w affected
r151056< r151056aw affected
r151054< r151054bw affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104113

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Double free in OmniOS and SmartOS ipmgmtd allows local users to crash the daemon
Source: CVE Program / CVE List V5
Vulnerability Description
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
Source: CVE Program / CVE List V5
Vulnerability Type
双重释放
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OmniOS OmniOS r151020 ~ r151054 -

II. Public POCs for CVE-2026-104113

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104113

请登录查看更多情报信息。

Other References for CVE-2026-104113 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104113

No comments yet


Leave a comment