Get real-time updates on Telegram
CVE-2026-104115: illumos-gate affected git revisions; +1 more affected products
Affected technology
illumos-gate · 2f172c55ef76964744bc62b4500ece87f3089b4d to before 6a2df4aa5381599179ab6afb3165db81960dee35; status changes: 6a2df4aa5381599179ab6afb3165db81960dee35 — unaffected
illumos
OmniOS · any to before r151054, r151058 to before r151058w; status changes: r151058w — unaffected, r151056 to before r151056aw; status changes: r151056aw — unaffected, r151054 to before r151054bw; status changes: r151054bw — unaffected
OmniOS
Component: Not specified by the source
File: usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, usr/src/cmd/fs.d/reparsed/reparsed.c
Attack conditions (Source advisory, CVSS 4.0): Local · Low privileges required · No user interaction required
What an attacker can do
A local user can crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. Source advisory’s CVSS 4.0 assessment (base score 5.4/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-121
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104115.html