Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15449— TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos illumos-gate是illumos组织开源的一个开源 Unix 操作系统。 illumos illumos-gate存在安全漏洞,该漏洞源于数据链路伪驱动(dld)中存在TOCTOU竞争条件漏洞,导致内核堆损坏,可能导致系统崩溃或进一步被利用。

AI Predicted 7.8 Difficulty: Hard EPSS 0.12% · P2

Affected Version Matrix 6

VendorProduct Version RangeStatus
illumos illumos-gate eae72b5b807baa9116e64502cbb278edf15f3146< 6959feb5b430411a4809b06c53dcdb42fb525eac affected
OmniOS OmniOS any< r151054 affected
r151058< r151058j affected
r151056< r151056aj affected
r151054< r151054bj affected
Triton Data Center SmartOS any< 202060709 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15449

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption
Source: CVE Program / CVE List V5
Vulnerability Description
A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_ioc_prop_common() in usr/src/uts/common/io/dld/dld_drv.c copies the dld_ioc_macprop_t ioctl header in once to read its pr_valsize field, sizes and allocates a kernel heap buffer from that value, and then copies the full request in a second time from the same unprivileged user address. A concurrent thread can enlarge pr_valsize between the two copyins, so the second copyin and the subsequent property handling write beyond the end of the undersized allocation and corrupt the kernel heap. An unprivileged local user, including one confined to a non-global zone that owns a datalink, can trigger this to panic the system. The resulting kernel heap corruption may be usable for further compromise.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
illumos illumos-gate 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
illumos illumos-gate是illumos组织开源的一个开源 Unix 操作系统。 illumos illumos-gate存在安全漏洞,该漏洞源于数据链路伪驱动(dld)中存在TOCTOU竞争条件漏洞,导致内核堆损坏,可能导致系统崩溃或进一步被利用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate eae72b5b807baa9116e64502cbb278edf15f3146 ~ 6959feb5b430411a4809b06c53dcdb42fb525eac -
OmniOS OmniOS any ~ r151054 -
Triton Data Center SmartOS any ~ 202060709 -

II. Public POCs for CVE-2026-15449

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15449

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-15449 (1)

Mailing List Discussions for CVE-2026-15449 (1)

Other References for CVE-2026-15449 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15449

No comments yet


Leave a comment