TOCTOU Flaw in illumos Data-Link Pseudo-Driver Affects Multiple Systems
CVE-2026-15449
What is CVE-2026-15449?
A time-of-check to time-of-use (TOCTOU) vulnerability exists in the illumos data-link pseudo-driver, specifically in the handling of ioctls DLDIOC_GETMACPROP and DLDIOC_SETMACPROP. This flaw arises when the system's kernel allocates a buffer for incoming user requests based on the pr_valsize field extracted from the ioctl header. Due to the design, a concurrent thread could alter the pr_valsize after the initial read but before the subsequent data copy occurs. This leads to potential buffer overflows, allowing an unprivileged local user, even from a limited environment, to manipulate the request and cause kernel heap corruption. The corruption could enable local denial-of-service conditions or may serve as a vector for further exploits.
Affected Version(s)
illumos-gate eae72b5b807baa9116e64502cbb278edf15f3146
OmniOS any
OmniOS any
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
