illumos 的 IP 管理守护进程(ipmgmtd)中存在一项缺失的授权检查漏洞,允许本地用户更改持久化 IP 多路径(IPMP)配置。具体而言,在文件 中的 ipmgmtd 门分发表里, 命令未要求 授权,尽管其处理函数 在设置 标志时会写入持久化的 配置。因此,无特权的本地用户可以将接口添加至现有的 IPMP 组,或将其从现有的 IPMP 组中移除。该操作不会立即更改运行时的配置,而是在下次应用存储的配置(例如系统启动时)才生效,可能导致网络连通性中断。该漏洞自 2021 年(illumos-gate 提交
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| illumos | illumos-gate | a73be61a80f7331c35adfa540bcf8f1546ff1e33< e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8 |
affected |
| OmniOS | OmniOS | r151042< r151054 |
affected |
r151058< r151058w |
affected | ||
r151056< r151056aw |
affected | ||
r151054< r151054bw |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| illumos | illumos-gate | a73be61a80f7331c35adfa540bcf8f1546ff1e33 ~ e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8 | - |
|
| OmniOS | OmniOS | r151042 ~ r151054 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102916 | 6.8 MEDIUM | Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani |
| CVE-2026-104112 | 6.8 MEDIUM | Missing release of passed file descriptors in illumos nscd allows local users to exhaust k |
| CVE-2026-104114 | 5.4 MEDIUM | NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae |
| CVE-2026-104115 | 5.4 MEDIUM | Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the |
| CVE-2026-104116 | 1.9 LOW | Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum |
No comments yet