Local User Denial of Service in IP Management Daemon of OmniOS and SmartOS
CVE-2026-104113

5.4MEDIUM

Key Information:

Vendor

OmniOS

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-104113?

A double free vulnerability in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows unprivileged local users to crash the daemon. This occurs when an authorization check fails during interface configuration updates, leading to the free of the caller's credentials twice. This flaw can be exploited via requests like IPMGMT_CMD_RESETIF, causing the ipmgmtd service to abort and positioning the svc:/network/ip-interface-management service into maintenance mode, thereby disrupting manageable IP configurations. This vulnerability originated in 2014 and is not present in the upstream illumos-gate.

Affected Version(s)

OmniOS x86 r151020

OmniOS x86 r151020

OmniOS x86 r151058

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert French
James Wynne III
Andy Fiddaman
.