CVE-2026-104113 PUBLISHED

Double free in OmniOS and SmartOS ipmgmtd allows local users to crash the daemon

Assigner: illumos
Reserved: 01.10.2026 Published: 09.10.2026 Updated: 09.10.2026

A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.4

Product Status

Vendor OmniOS
Product OmniOS
Versions Default: affected
  • affected from r151020 to r151054 (excl.)
  • affected from r151058 to r151058w (excl.)
  • affected from r151056 to r151056aw (excl.)
  • affected from r151054 to r151054bw (excl.)

Solutions

Update your illumos distribution to one that includes the fix for this issue.

Credits

  • Robert French finder
  • James Wynne III finder
  • Andy Fiddaman remediation developer

References

Problem Types

  • CWE-415 Double Free CWE