illumos 重解析点守护进程(reparsed)中存在基于栈的缓冲区溢出漏洞,允许本地用户导致该守护进程崩溃。 中的 函数属于 nfs-basic 重解析插件的一部分,该函数在将重解析字符串的主机和路径组件复制到一个固定大小为 1024 字节的栈缓冲区时,未对它们的长度进行检查。 处的 reparsed door 对所有用户可读,且 door 服务器不验证调用者的凭证,因此未经授权的本地用户可以发送包含过长主机或路径组件的 nfs-basic 请求,从而溢出缓冲区。在启用了栈保护的系统上(默认启用),这会导致
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| illumos | illumos-gate | 2f172c55ef76964744bc62b4500ece87f3089b4d< 6a2df4aa5381599179ab6afb3165db81960dee35 |
affected |
| OmniOS | OmniOS | any< r151054 |
affected |
r151058< r151058w |
affected | ||
r151056< r151056aw |
affected | ||
r151054< r151054bw |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| illumos | illumos-gate | 2f172c55ef76964744bc62b4500ece87f3089b4d ~ 6a2df4aa5381599179ab6afb3165db81960dee35 | - |
|
| OmniOS | OmniOS | any ~ r151054 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102916 | 6.8 MEDIUM | Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani |
| CVE-2026-104112 | 6.8 MEDIUM | Missing release of passed file descriptors in illumos nscd allows local users to exhaust k |
| CVE-2026-104114 | 5.4 MEDIUM | NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae |
| CVE-2026-104117 | 1.9 LOW | Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou |
| CVE-2026-104116 | 1.9 LOW | Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum |
No comments yet