Stack-Based Buffer Overflow in illumos Reparse Point Daemon Affects Local Users
CVE-2026-104115
What is CVE-2026-104115?
A stack-based buffer overflow vulnerability exists in the illumos reparse point daemon that can be exploited by local users. This flaw stems from the get_fs_locations() function, which fails to validate the length of the host and path components before copying them into a fixed-size stack buffer. Because the reparsed door server does not authenticate callers, any unprivileged local user can send an overly long nfs-basic request, leading to a buffer overflow. This results in the daemon crashing or entering an unrecoverable state, which could inadvertently disrupt the service. The vulnerability has persisted since 2009 and impacts all illumos distributions prior to the specified commit.
Affected Version(s)
illumos-gate x86 2f172c55ef76964744bc62b4500ece87f3089b4d < 6a2df4aa5381599179ab6afb3165db81960dee35
OmniOS any
OmniOS any
