CVE-2026-104115
Awaiting Analysis Awaiting Analysis - Queue

Stack-Based Buffer Overflow in illumos Reparse Daemon

Vulnerability report for CVE-2026-104115, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: illumos

Description

A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
illumos illumos-gate 2f172c55ef76964744bc62b4500ece87f3089b4d
OmniOS OmniOS any
OmniOS OmniOS r151058
OmniOS OmniOS r151056
OmniOS OmniOS r151054

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104115 is a stack-based buffer overflow in the illumos reparse point daemon (reparsed). A local user can crash the daemon by sending an NFS reparse request with an overlong host or path component. The flaw exists in the get_fs_locations() function which copies these components into a fixed 1024-byte stack buffer without length validation. The daemon's door server is readable by all users and lacks caller credential checks, allowing unprivileged local exploitation.

Detection Guidance

Check if the reparsed service is running with: svcs -a | grep reparse. Monitor for service crashes or maintenance mode. Review logs for door server errors or abnormal terminations in /var/adm/messages or system logs.

Impact Analysis

This vulnerability allows a local attacker to crash the reparsed daemon, potentially disabling the svc:/system/filesystem/reparse service. On systems with stack protection enabled (default), repeated exploitation places the service into maintenance mode. Since the service is disabled by default, the primary impact is denial-of-service through service disruption.

Compliance Impact

The vulnerability allows local users to crash the reparsed daemon via stack-based buffer overflow, potentially disrupting NFS reparse services. This could lead to service unavailability, which may impact data access and processing. However, the provided context does not specify direct impacts on GDPR or HIPAA compliance.

Mitigation Strategies

Apply the patch from illumos-gate commit 6a2df4aa. Disable the reparsed service if not needed: svcadm disable svc:/system/filesystem/reparse. Restrict access to /var/run/reparsed_door by setting proper permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104115. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart