Get real-time updates on Telegram
CVE-2026-104114: illumos-gate affected git revisions; +1 more affected products
Affected technology
illumos-gate · 6ba597c56d749c61b4f783157f63196d7b2445f0 to before 0f1064d97f1a43778ddf87d4e438b99872aed1a0; status changes: 0f1064d97f1a43778ddf87d4e438b99872aed1a0 — unaffected
illumos
OmniOS · any to before r151054, r151058 to before r151058w; status changes: r151058w — unaffected, r151056 to before r151056aw; status changes: r151056aw — unaffected, r151054 to before r151054bw; status changes: r151054bw — unaffected
OmniOS
Component: Not specified by the source
File: usr/src/cmd/cmd-inet/lib/nwamd/door_if.c
Attack conditions (Source advisory, CVSS 4.0): Local · Low privileges required · No user interaction required
What an attacker can do
A local user can crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Source advisory’s CVSS 4.0 assessment (base score 5.4/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-476
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104114.html