Stack-Based Buffer Overflow in illumos Reparse Point Daemon Affects Local Users
CVE-2026-104115

5.4MEDIUM

Key Information:

Vendor

Illumos

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104115?

A stack-based buffer overflow vulnerability exists in the illumos reparse point daemon that can be exploited by local users. This flaw stems from the get_fs_locations() function, which fails to validate the length of the host and path components before copying them into a fixed-size stack buffer. Because the reparsed door server does not authenticate callers, any unprivileged local user can send an overly long nfs-basic request, leading to a buffer overflow. This results in the daemon crashing or entering an unrecoverable state, which could inadvertently disrupt the service. The vulnerability has persisted since 2009 and impacts all illumos distributions prior to the specified commit.

Affected Version(s)

illumos-gate x86 2f172c55ef76964744bc62b4500ece87f3089b4d < 6a2df4aa5381599179ab6afb3165db81960dee35

OmniOS any

OmniOS any

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert French
James Wynne III
Andy Fiddaman
.