CVE-2026-104114 PUBLISHED

NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon

Assigner: illumos
Reserved: 01.10.2026 Published: 09.10.2026 Updated: 09.10.2026

A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.4

Product Status

Vendor illumos
Product illumos-gate
Versions Default: unaffected
  • affected from 6ba597c56d749c61b4f783157f63196d7b2445f0 to 0f1064d97f1a43778ddf87d4e438b99872aed1a0 (excl.)
Vendor OmniOS
Product OmniOS
Versions Default: affected
  • affected from any to r151054 (excl.)
  • affected from r151058 to r151058w (excl.)
  • affected from r151056 to r151056aw (excl.)
  • affected from r151054 to r151054bw (excl.)

Workarounds

Systems that use the default svc:/network/physical:default service instead of svc:/network/physical:nwam do not run nwamd and are not exposed.

Solutions

Update your illumos distribution to one that includes the fix for this issue.

Credits

  • Robert French finder
  • James Wynne III finder
  • Andy Fiddaman remediation developer

References

Problem Types

  • CWE-476 NULL Pointer Dereference CWE