๐Ÿ” CVE Alert

CVE-2026-104113

UNKNOWN 0.0

Double free in OmniOS and SmartOS ipmgmtd allows local users to crash the daemon

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.

CWE CWE-415
Vendor omnios
Product omnios
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for omnios omnios

Be the first to know when new unknown vulnerabilities affecting omnios omnios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

OmniOS / OmniOS
r151020 < r151054 r151058 < r151058w r151056 < r151056aw r151054 < r151054bw

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
illumos.topicbox.com: https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers github.com: https://github.com/omniosorg/illumos-omnios/commit/670d853f335203ce8a66126cdbb25bfdba973036 github.com: https://github.com/TritonDataCenter/illumos-joyent/commit/TBD

Credits

Robert French James Wynne III Andy Fiddaman