NULL Pointer Dereference Vulnerability in illumos Network Auto-Magic Daemon
CVE-2026-104114

5.4MEDIUM

Key Information:

Vendor

Illumos

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104114?

A NULL pointer dereference vulnerability in the illumos Network Auto-Magic daemon (nwamd) can be exploited by local users to crash the daemon, interrupting network configuration services. This occurs when nwamd_door_switch() processes requests without validating supplied arguments or user credentials, allowing unprivileged users to issue door_call() commands without proper data. Repeated exploitation leads to the svc:/network/physical:nwam service entering maintenance mode, which halts the automatic network configuration process. This vulnerability has existed since 2010 and impacts all illumos distributions prior to a specific code commit.

Affected Version(s)

illumos-gate x86 6ba597c56d749c61b4f783157f63196d7b2445f0 < 0f1064d97f1a43778ddf87d4e438b99872aed1a0

OmniOS any

OmniOS any

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert French
James Wynne III
Andy Fiddaman
.