CVE-2026-104112
Received Received - Intake

Memory Exhaustion in illumos nscd

Vulnerability report for CVE-2026-104112, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: illumos

Description

A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
illumos illumos-gate cb5caa98562cf06753163f558cbcfe30b8f4673a
OmniOS OmniOS any
OmniOS OmniOS r151058
OmniOS OmniOS r151056
OmniOS OmniOS r151054

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-772 The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a missing resource release in the illumos name service cache daemon (nscd). A local user can exploit this by repeatedly passing unused file descriptors to nscd via door calls, causing the daemon's file descriptor table to grow without bound in kernel memory. This leads to a denial of service for nscd and can make other processes unresponsive across all zones on the host.

Detection Guidance

To detect this vulnerability, monitor nscd for excessive file descriptor usage. Check if nscd is running with an unlimited file descriptor limit using 'prctl -n file_descriptor_limit -i process $(pgrep nscd)'. Look for unusually high file descriptor counts in 'pfiles $(pgrep nscd)' or 'lsof -p $(pgrep nscd)'. If descriptors grow without bound, the system may be vulnerable.

Impact Analysis

This vulnerability allows an unprivileged local user to exhaust kernel memory, causing nscd to fail and potentially making other processes unresponsive. It affects all zones on the host, including non-global zones, and can lead to system instability or crashes.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt critical services. Resource exhaustion in nscd may lead to system instability, potentially affecting data availability and integrity required by these regulations.

Mitigation Strategies

Apply the patch from illumos-gate commit af810a72 or later to fix the missing resource release in nscd. Monitor system memory usage for nscd and file descriptor exhaustion. Restrict local user access to the nscd door at /var/run/name_service_door if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104112. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart