{"id":"CVE-2026-104114","title":"A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon","summary":"A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking…","severity":"none","cwe":["CWE-476"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T17:16:44.647","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104114","references":[{"url":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"},{"url":"https://illumos.org/issues/18495","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"}],"tags":["nvd"],"ingestedAt":"2026-10-09T16:02:33.375Z","slug":"CVE-2026-104114","body":"## Overview\n\nA NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}