CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-104114: illumos-gate affected git revisions; +1 more affected products

Affected technology

illumos-gate · 6ba597c56d749c61b4f783157f63196d7b2445f0 to before 0f1064d97f1a43778ddf87d4e438b99872aed1a0; status changes: 0f1064d97f1a43778ddf87d4e438b99872aed1a0 — unaffected
illumos

OmniOS · any to before r151054, r151058 to before r151058w; status changes: r151058w — unaffected, r151056 to before r151056aw; status changes: r151056aw — unaffected, r151054 to before r151054bw; status changes: r151054bw — unaffected
OmniOS

Component: Not specified by the source
File: usr/src/cmd/cmd-inet/lib/nwamd/door_if.c

Attack conditions (Source advisory, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

A local user can crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Source advisory’s CVSS 4.0 assessment (base score 5.4/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-476
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104114.html