Missing Authorization Check in illumos Zones Statistics Daemon Affects Local Users
CVE-2026-104116
What is CVE-2026-104116?
A flaw exists in the illumos zones statistics daemon preventing proper authorization checks, enabling local users to disrupt the zonestat service across different zones. The vulnerability arises from the door server procedure zsd_server() failing to authenticate the requester, allowing any user to send the ZSD_CMD_NEW_ZONE command unverified. This mishandling can prompt zonestatd to unintentionally recreate its door file, causing service interruptions as new requests are issued while the file is being replaced. Moreover, the response duration can indicate whether specific zone IDs correspond to active zones, presenting a potential risk for information leakage. This issue has persisted since 2010 and affects all illumos distributions preceding the pertinent commit.
Affected Version(s)
illumos-gate x86 efd4c9b63ad77503c101fc6c2ed8ba96c9d52964 < 865b58d24a0f1a31c838bffc3a7193d3345fe5ba
OmniOS any
OmniOS any
