CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-104116: illumos-gate affected git revisions; +1 more affected products

Affected technology

illumos-gate · efd4c9b63ad77503c101fc6c2ed8ba96c9d52964 to before 865b58d24a0f1a31c838bffc3a7193d3345fe5ba; status changes: 865b58d24a0f1a31c838bffc3a7193d3345fe5ba — unaffected
illumos

OmniOS · any to before r151054, r151058 to before r151058w; status changes: r151058w — unaffected, r151056 to before r151056aw; status changes: r151056aw — unaffected, r151054 to before r151054bw; status changes: r151054bw — unaffected
OmniOS

Component: Not specified by the source
File: usr/src/cmd/zonestat/zonestatd/zonestatd.c

Attack conditions (Source advisory, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

An unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. Source advisory’s CVSS 4.0 assessment (base score 1.9/10) rates confidentiality and availability impact as low; integrity impact as none.

Published

CWE
CWE-862
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104116.html