illumos 网络自动配置守护进程(nwamd)存在空指针解引用漏洞,本地用户可利用该漏洞使守护进程崩溃。在文件 中,函数 在检查是否提供了请求数据以及验证调用者身份凭证之前,便向调用者的请求结构写入数据。由于 上的 nwamd 门(door)对所有本地用户均可访问,未经特权提升的用户可以通过调用 且不附带任何参数数据来触发 nwamd 崩溃;重复执行此类调用会导致 服务进入维护模式,从而停止自动网络配置。nwamd 仅在 服务启用时运行,而该服务默认情况下并未启用。此漏洞自 2010 年(illumos-gat
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| illumos | illumos-gate | 6ba597c56d749c61b4f783157f63196d7b2445f0 ~ 0f1064d97f1a43778ddf87d4e438b99872aed1a0 | - |
|
| OmniOS | OmniOS | any ~ r151054 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102916 | 6.8 MEDIUM | Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani |
| CVE-2026-104112 | 6.8 MEDIUM | Missing release of passed file descriptors in illumos nscd allows local users to exhaust k |
| CVE-2026-104115 | 5.4 MEDIUM | Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the |
| CVE-2026-104117 | 1.9 LOW | Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou |
| CVE-2026-104116 | 1.9 LOW | Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum |
No comments yet