Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104114— NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos 网络自动配置守护进程(nwamd)存在空指针解引用漏洞,本地用户可利用该漏洞使守护进程崩溃。在文件 中,函数 在检查是否提供了请求数据以及验证调用者身份凭证之前,便向调用者的请求结构写入数据。由于 上的 nwamd 门(door)对所有本地用户均可访问,未经特权提升的用户可以通过调用 且不附带任何参数数据来触发 nwamd 崩溃;重复执行此类调用会导致 服务进入维护模式,从而停止自动网络配置。nwamd 仅在 服务启用时运行,而该服务默认情况下并未启用。此漏洞自 2010 年(illumos-gat

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104114

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon
Source: CVE Program / CVE List V5
Vulnerability Description
A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate 6ba597c56d749c61b4f783157f63196d7b2445f0 ~ 0f1064d97f1a43778ddf87d4e438b99872aed1a0 -
OmniOS OmniOS any ~ r151054 -

II. Public POCs for CVE-2026-104114

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104114

请登录查看更多情报信息。

Other References for CVE-2026-104114 (3)

Same Patch Batch · illumos · 2026-10-09 · 6 CVEs total

CVE-2026-102916 6.8 MEDIUM Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani
CVE-2026-104112 6.8 MEDIUM Missing release of passed file descriptors in illumos nscd allows local users to exhaust k
CVE-2026-104115 5.4 MEDIUM Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the
CVE-2026-104117 1.9 LOW Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou
CVE-2026-104116 1.9 LOW Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum

IV. Related Vulnerabilities

V. Comments for CVE-2026-104114

No comments yet


Leave a comment