Description
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
Published: 2026-10-09
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS causes the daemon to abort when it frees a credential object twice. The bug is triggered by an unprivileged local user who sends a door request that modifies interface configuration, such as IPMGMT_CMD_RESETIF. When the authorization check fails the code path frees the caller’s credential object a second time, leading to a crash that terminates the daemon. The crash places the svc:/network/ip-interface-management service into maintenance mode, disabling all IP interface configuration until the service is restarted.

Affected Systems

The vulnerability affects OmniOS releases r151020 and later and any SmartOS installations prior to the fix. The affected component is the ipmgmttd daemon, which is a core service for network interface management in these illumos distributions.

Risk and Exploitability

The CVSS score of 5.4 places this issue in the moderate severity range. EPSS data is not available and the vulnerability is not listed in CISA KEV. The attack vector is local and requires an unprivileged user to have the ability to send door requests; it cannot be abused remotely. The impact is a denial of service to network interface management operations, which can affect service availability on the host that requires dynamic IP configuration.

Generated by OpenCVE AI on October 9, 2026 at 16:03 UTC.

Remediation

Vendor Solution

Update your illumos distribution to one that includes the fix for this issue.


OpenCVE Recommended Actions

  • Upgrade to a patched release of OmniOS or SmartOS that includes the commit 670d853f335203ce8a66126cdbb25bfdba973036 or later, thereby applying the double‑free fix.
  • After the upgrade, restart or re‑enable the svc:/network/ip-interface-management service to ensure it exits maintenance mode and processes new IP configuration requests.
  • Verify that the service is running and that IP interface configuration commands succeed; consider monitoring ipmgmtd logs for unexpected aborts to detect any remaining issues.

Generated by OpenCVE AI on October 9, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Omnios
Omnios omnios
Vendors & Products Omnios
Omnios omnios

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
Title Double free in OmniOS and SmartOS ipmgmtd allows local users to crash the daemon
Weaknesses CWE-415
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T16:45:51.552Z

Reserved: 2026-10-01T18:07:53.956Z

Link: CVE-2026-104113

cve-icon Vulnrichment

Updated: 2026-10-09T16:15:21.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:07.270

Modified: 2026-10-09T17:16:44.493

Link: CVE-2026-104113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T16:15:08Z

Weaknesses