{"id":"CVE-2026-104112","summary":"Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory","details":"A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.","modified":"2026-10-10T07:06:17.702131417Z","published":"2026-10-09T14:19:29.399Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"r151058"},{"fixed":"r151058w"},{"introduced":"r151056"},{"fixed":"r151056aw"},{"introduced":"r151054"},{"fixed":"r151054bw"},{"introduced":"any"},{"fixed":"r151054"}]}],"cna_assigner":"illumos","cwe_ids":["CWE-772"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104112.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104112.json"},{"type":"PACKAGE","url":"https://github.com/illumos/illumos-gate"},{"type":"FIX","url":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae"},{"type":"WEB","url":"https://illumos.org"},{"type":"REPORT","url":"https://illumos.org/issues/18494"},{"type":"ARTICLE","url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104112"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/illumos/illumos-gate","events":[{"introduced":"cb5caa98562cf06753163f558cbcfe30b8f4673a"},{"fixed":"af810a72c09944e884ec695e8dbf1702a4f424ae"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104112.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["247441696752788331118226190469695403633","279513019286725997127904594211621133098","164005998286530920828951139008139806730","57467878122903355204948137052594962117","104649542058458615904218921818734802427","332818971004924014367089398481820307042","248917546999319425058569536913261642200","210569138948482621675142059712983400434","274721550446062246319067468544476092477","195086366322672202582979300123816561506","4060698525438301809093039651038118747","186070300260410314093025375752552807275","147032550356996340168716136832433653437","312716667382607561906357928535498872602","183448912466972239944156400738152559338","21234261845396199291105227454093805414","309641266826378806152829580720659199865","323671910981714405064687395298318888973","257779611946771884866423444954562011005","86748267980253259501735033194128761775","114407476855680574854495313157443386283","291959756791318933558180182956278181250","143829138919115002901209531631766833265","234939684468432776145810327716702329823","49311810866389310516142948511477961732","40302339977908282185929634525053061986","144248260343643474222981346656269689831","103308863523665764233745842661353093002","72847804598058752989475997373585467628","131369305383549648075471835024313297996"],"threshold":0.9},"id":"CVE-2026-104112-1b3edaed","signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","target":{"file":"usr/src/cmd/nscd/nscd_selfcred.c"}},{"digest":{"function_hash":"126222657128090057554551853022069994315","length":4477},"id":"CVE-2026-104112-1e1c195e","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","target":{"file":"usr/src/cmd/nscd/nscd_selfcred.c","function":"_nscd_proc_iamhere"},"deprecated":false},{"digest":{"function_hash":"23803840365219291629769208149536966904","length":962},"id":"CVE-2026-104112-a0c7dd75","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","target":{"file":"usr/src/cmd/nscd/nscd_frontend.c","function":"if_selfcred_return_per_user_door"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"129012098082254568253659653811947553478","length":3295},"id":"CVE-2026-104112-caf79366","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","target":{"file":"usr/src/cmd/nscd/nscd_frontend.c","function":"_nscd_setup_server"}},{"digest":{"line_hashes":["327669765148877740964501560410496764286","190353109025385723681436308949677581545","325651405042757944772240307573374756832","278632062812794289580393864903600559694","102408792762546369151611233996820852645","71817555497811212695222451931534935467","333084563902802634507368834518857661566","37019789963894903287914102321985079823","212298463843930443424720717887414261515","18413303929547140398619279395519099843","46769922709258737313098741297680808935","195313986175595508555971543241189340333","234074976718645720160568552948433711436","244043073754485225611572103574864110737","16903281568772524427562136038246466778","182153353475030625247122834390980473383","163332468130307486794057471882529920717","186782060574819225397174352948085340920","147800688499890035654359991558990436900","3616793092474058789722368791394044937","58678879072302005740855070189992716894","76407974689879986944785662579852056008","218771747812153672591281264609548224939","191597830452661138923837492753274340341","17720691647544796406781281309084523887","317795400713071426265067695072542595120","186117966533413949070173626778621112935","213607630933794390028112992568224460963","66389704111463579351375739954302423610","338442535314552942509629817324013283772","118059923962472411468709983668643662613","267924049141999811745660641717393783213","196100936753761556970725287190103691343","152083103322030825062758645278442386023","22967099421722396606893368628873902495","151701877132627159956677089480945076086","39721077117733733381846435061900444009","181730642053369306662216626718245088451","296690447565431934970320791512672498435","227843446400188284611063304734987406035","229625074863413587127986658601601747103","297314784225589356423930229567631944774","216193810475256099209050070967550000977","208420740415996272143039488945927401460","280613306880167475078781488947571237718","178010833235115785991022988772025014644","69216505527280613042968820668966206158","123703977853300043114968504619162167935","324889313751196284558473573948178284618","8984976829531442978170475996692722283","173061837115309319337283391787997531578","196415076409381670327762840344912333958","310660608721835866016431059436881462293","99483388666155350186576899727440256287","8580208962501208750601445563394732589","283676717569571862783955996654608354141","338172478115349000522463381769525061554","192823181512499086684527021049484615612","263841690454932305560509555627790400028","109933056298344569210926399183500068511","209025994918038014679479427808585132101","216193810475256099209050070967550000977","231986696963902651262177335339796021608","222469169487390111924239901168917539016","189533330135001168641926827854158288252","183140454455978532801661834506334800425"],"threshold":0.9},"id":"CVE-2026-104112-ce494ade","signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","target":{"file":"usr/src/cmd/nscd/nscd_frontend.c"},"deprecated":false},{"digest":{"function_hash":"35751038206727567551513394570726343545","length":3837},"id":"CVE-2026-104112-d45ad950","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","target":{"file":"usr/src/cmd/nscd/nscd_frontend.c","function":"switcher"},"deprecated":false},{"target":{"file":"usr/src/cmd/nscd/nscd_selfcred.h"},"deprecated":false,"digest":{"line_hashes":["84793310123242212663841392599760749068","234938813010665443688867960575017495826","89020593678971792000635024680114158706","47416490408619342708827004309168079727","10303606229579907698197664022361921861","134789470030343672013999611597115067371","193850550014830241731382284858666883382","208152257276636901006006885065375938138","17883363642346757881111864079110001259","60500766592362595435219086489384524898","177465382169558236446368730911690320903","293712378701374071739177624970972818482","27357042309075340331945193284499704605","74116185889841555307871104059931065843","233164725453826913496134064310719866150","73162751224199074478066776562596088964"],"threshold":0.9},"id":"CVE-2026-104112-f7bdfec3","signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae"}],"vanir_signatures_modified":"2026-10-10T07:06:17Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P"}]}