{"id":"CVE-2026-104113","title":"A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon","summary":"A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmt…","severity":"none","cwe":["CWE-415"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T17:16:44.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104113","references":[{"url":"https://github.com/TritonDataCenter/illumos-joyent/commit/TBD","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"},{"url":"https://github.com/omniosorg/illumos-omnios/commit/670d853f335203ce8a66126cdbb25bfdba973036","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"}],"tags":["nvd"],"ingestedAt":"2026-10-09T16:02:33.374Z","slug":"CVE-2026-104113","body":"## Overview\n\nA double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}