Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104115— Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos 重解析点守护进程(reparsed)中存在基于栈的缓冲区溢出漏洞,允许本地用户导致该守护进程崩溃。 中的 函数属于 nfs-basic 重解析插件的一部分,该函数在将重解析字符串的主机和路径组件复制到一个固定大小为 1024 字节的栈缓冲区时,未对它们的长度进行检查。 处的 reparsed door 对所有用户可读,且 door 服务器不验证调用者的凭证,因此未经授权的本地用户可以发送包含过长主机或路径组件的 nfs-basic 请求,从而溢出缓冲区。在启用了栈保护的系统上(默认启用),这会导致

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1548.002 · Bypass User Account Control

Affected Version Matrix 5

VendorProduct Version RangeStatus
illumos illumos-gate 2f172c55ef76964744bc62b4500ece87f3089b4d< 6a2df4aa5381599179ab6afb3165db81960dee35 affected
OmniOS OmniOS any< r151054 affected
r151058< r151058w affected
r151056< r151056aw affected
r151054< r151054bw affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104115

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon
Source: CVE Program / CVE List V5
Vulnerability Description
A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate 2f172c55ef76964744bc62b4500ece87f3089b4d ~ 6a2df4aa5381599179ab6afb3165db81960dee35 -
OmniOS OmniOS any ~ r151054 -

II. Public POCs for CVE-2026-104115

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104115

请登录查看更多情报信息。

Other References for CVE-2026-104115 (3)

Same Patch Batch · illumos · 2026-10-09 · 6 CVEs total

CVE-2026-102916 6.8 MEDIUM Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani
CVE-2026-104112 6.8 MEDIUM Missing release of passed file descriptors in illumos nscd allows local users to exhaust k
CVE-2026-104114 5.4 MEDIUM NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae
CVE-2026-104117 1.9 LOW Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou
CVE-2026-104116 1.9 LOW Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum

IV. Related Vulnerabilities

V. Comments for CVE-2026-104115

No comments yet


Leave a comment