๐Ÿ” CVE Alert

CVE-2026-104114

UNKNOWN 0.0

NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.

CWE CWE-476
Vendor illumos
Product illumos-gate
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for illumos illumos-gate

Be the first to know when new unknown vulnerabilities affecting illumos illumos-gate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

illumos / illumos-gate
6ba597c56d749c61b4f783157f63196d7b2445f0 < 0f1064d97f1a43778ddf87d4e438b99872aed1a0
OmniOS / OmniOS
any < r151054 r151058 < r151058w r151056 < r151056aw r151054 < r151054bw

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
illumos.topicbox.com: https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers illumos.org: https://illumos.org/issues/18495 github.com: https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0

Credits

Robert French James Wynne III Andy Fiddaman