Local Resource Exhaustion Vulnerability in Illumos Name Service Cache Daemon
CVE-2026-104112

6.8MEDIUM

Key Information:

Vendor

Illumos

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104112?

A vulnerability in the illumos name service cache daemon (nscd) allows local users to exploit a flaw in resource handling, leading to a denial of service. The nscd door server does not adequately release file descriptors, allowing unprivileged local users, including those in non-global zones, to repeatedly send descriptors through the door call. This improperly managed resource can cause the file descriptor table of nscd to expand indefinitely in kernel memory, potentially rendering processes across all zones unresponsive. This persistent issue has remained unaddressed since its introduction in 2006.

Affected Version(s)

illumos-gate x86 cb5caa98562cf06753163f558cbcfe30b8f4673a

OmniOS any

OmniOS any

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert French
James Wynne III
Dan McDonald
.