CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-104115: illumos-gate affected git revisions; +1 more affected products

Affected technology

illumos-gate · 2f172c55ef76964744bc62b4500ece87f3089b4d to before 6a2df4aa5381599179ab6afb3165db81960dee35; status changes: 6a2df4aa5381599179ab6afb3165db81960dee35 — unaffected
illumos

OmniOS · any to before r151054, r151058 to before r151058w; status changes: r151058w — unaffected, r151056 to before r151056aw; status changes: r151056aw — unaffected, r151054 to before r151054bw; status changes: r151054bw — unaffected
OmniOS

Component: Not specified by the source
File: usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, usr/src/cmd/fs.d/reparsed/reparsed.c

Attack conditions (Source advisory, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

A local user can crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. Source advisory’s CVSS 4.0 assessment (base score 5.4/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-121
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104115.html