CVE-2026-104113
Received Received - Intake

Double Free in OmniOS and SmartOS IP Management Daemon

Vulnerability report for CVE-2026-104113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: illumos

Description

A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
OmniOS OmniOS r151020
OmniOS OmniOS r151058
OmniOS OmniOS r151056
OmniOS OmniOS r151054

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a double free issue in the IP management daemon (ipmgmtd) of OmniOS and SmartOS. A local user can crash the daemon by sending a specific door request that modifies interface configuration. The function ipmgmt_handler() frees the caller's credential twice: once immediately after reading the user ID and again on the error path if authorization fails. This causes ipmgmtd to abort and can repeatedly place the IP interface management service into maintenance, preventing further configuration.

Detection Guidance

Check if the ipmgmtd service is in maintenance mode or crashed. Use commands like 'svcs -x svc:/network/ip-interface-management' to verify service status. Monitor system logs for ipmgmtd crashes or repeated service failures.

Impact Analysis

An unprivileged local user could exploit this to crash the ipmgmtd service, disrupting IP interface management. Repeated exploitation may keep the service in a failed state, preventing legitimate users from configuring network interfaces. This could lead to network downtime or loss of remote access.

Mitigation Strategies

Apply the vendor patch if available for OmniOS or SmartOS. Restart the ipmgmtd service if it is in maintenance mode. Restrict local user access to prevent unauthorized door requests until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart