Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104116— Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enumerate running zones

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos 区域统计守护进程(zonestatd)中存在缺少授权检查的问题,允许处于任意区域中的本地用户中断其他区域中的 zonestat 服务,并探测哪些区域正在运行。 zonestatd 的门服务器过程函数 zsd_server()(位于文件 usr/src/cmd/zonestat/zonestatd/zonestatd.c 中)处理 ZSD_CMD_NEW_ZONE 命令。该命令本应由 zoneadmd 发送,但函数在接收和处理该命令时未对调用者的身份凭证进行验证。由于 zonestatd 的门接口对所

CVSS 1.9 · Low

Affected Version Matrix 5

VendorProduct Version RangeStatus
illumos illumos-gate efd4c9b63ad77503c101fc6c2ed8ba96c9d52964< 865b58d24a0f1a31c838bffc3a7193d3345fe5ba affected
OmniOS OmniOS any< r151054 affected
r151058< r151058w affected
r151056< r151056aw affected
r151054< r151054bw affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104116

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enumerate running zones
Source: CVE Program / CVE List V5
Vulnerability Description
A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt zonestat in other zones and to determine which zones are running. The zonestatd door server procedure, zsd_server() in usr/src/cmd/zonestat/zonestatd/zonestatd.c, handles the ZSD_CMD_NEW_ZONE command, which is intended to be sent by zoneadmd, without checking the caller's credentials. Because the zonestatd door is accessible to all users in every zone, an unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. The time taken to handle the command also reveals whether a given zone ID belongs to a running zone. The flaw has existed since 2010 (illumos-gate commit efd4c9b6), and affects any illumos distribution prior to illumos-gate commit 865b58d2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate efd4c9b63ad77503c101fc6c2ed8ba96c9d52964 ~ 865b58d24a0f1a31c838bffc3a7193d3345fe5ba -
OmniOS OmniOS any ~ r151054 -

II. Public POCs for CVE-2026-104116

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104116

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104116 (2)

Vendor Advisories for CVE-2026-104116 (1)

Same Patch Batch · illumos · 2026-10-09 · 6 CVEs total

CVE-2026-102916 6.8 MEDIUM Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani
CVE-2026-104112 6.8 MEDIUM Missing release of passed file descriptors in illumos nscd allows local users to exhaust k
CVE-2026-104114 5.4 MEDIUM NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae
CVE-2026-104115 5.4 MEDIUM Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the
CVE-2026-104117 1.9 LOW Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP grou

IV. Related Vulnerabilities

V. Comments for CVE-2026-104116

No comments yet


Leave a comment