Impact
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS causes the daemon to abort when it frees a credential object twice. The bug is triggered by an unprivileged local user who sends a door request that modifies interface configuration, such as IPMGMT_CMD_RESETIF. When the authorization check fails the code path frees the caller’s credential object a second time, leading to a crash that terminates the daemon. The crash places the svc:/network/ip-interface-management service into maintenance mode, disabling all IP interface configuration until the service is restarted.
Affected Systems
The vulnerability affects OmniOS releases r151020 and later and any SmartOS installations prior to the fix. The affected component is the ipmgmttd daemon, which is a core service for network interface management in these illumos distributions.
Risk and Exploitability
The CVSS score of 5.4 places this issue in the moderate severity range. EPSS data is not available and the vulnerability is not listed in CISA KEV. The attack vector is local and requires an unprivileged user to have the ability to send door requests; it cannot be abused remotely. The impact is a denial of service to network interface management operations, which can affect service availability on the host that requires dynamic IP configuration.
OpenCVE Enrichment