Get real-time updates on Telegram
CVE-2026-104116: illumos-gate affected git revisions; +1 more affected products
Affected technology
illumos-gate · efd4c9b63ad77503c101fc6c2ed8ba96c9d52964 to before 865b58d24a0f1a31c838bffc3a7193d3345fe5ba; status changes: 865b58d24a0f1a31c838bffc3a7193d3345fe5ba — unaffected
illumos
OmniOS · any to before r151054, r151058 to before r151058w; status changes: r151058w — unaffected, r151056 to before r151056aw; status changes: r151056aw — unaffected, r151054 to before r151054bw; status changes: r151054bw — unaffected
OmniOS
Component: Not specified by the source
File: usr/src/cmd/zonestat/zonestatd/zonestatd.c
Attack conditions (Source advisory, CVSS 4.0): Local · Low privileges required · No user interaction required
What an attacker can do
An unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. Source advisory’s CVSS 4.0 assessment (base score 1.9/10) rates confidentiality and availability impact as low; integrity impact as none.
- CWE
- CWE-862
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 22:06:25.045838+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 21:08:49.498434+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104116.html