{"id":"CVE-2026-104114","summary":"NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon","details":"A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.","modified":"2026-10-10T07:06:14.314463991Z","published":"2026-10-09T14:22:14.611Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104114.json","unresolved_ranges":[{"extracted_events":[{"introduced":"r151058"},{"fixed":"r151058w"},{"introduced":"r151056"},{"fixed":"r151056aw"},{"introduced":"r151054"},{"fixed":"r151054bw"},{"introduced":"any"},{"fixed":"r151054"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"illumos","cwe_ids":["CWE-476"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104114.json"},{"type":"PACKAGE","url":"https://github.com/illumos/illumos-gate"},{"type":"FIX","url":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0"},{"type":"WEB","url":"https://illumos.org"},{"type":"REPORT","url":"https://illumos.org/issues/18495"},{"type":"ARTICLE","url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104114"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/illumos/illumos-gate","events":[{"introduced":"6ba597c56d749c61b4f783157f63196d7b2445f0"},{"fixed":"0f1064d97f1a43778ddf87d4e438b99872aed1a0"}]}],"database_specific":{"vanir_signatures":[{"target":{"function":"nwam_backend_door_server","file":"usr/src/lib/libnwam/common/libnwam_backend.c"},"deprecated":false,"digest":{"function_hash":"182257522554449769069343743966968080892","length":2793},"id":"CVE-2026-104114-8758d4ee","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0","target":{"file":"usr/src/cmd/cmd-inet/lib/nwamd/door_if.c"},"deprecated":false,"digest":{"line_hashes":["186332791323576956723887412042360141499","254424715392401920924313611307373415623","6771889911526717672553369584756059091","265248265874785983907488398052940856246"],"threshold":0.9},"id":"CVE-2026-104114-a5a15cbd"},{"signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0","target":{"file":"usr/src/lib/libnwam/common/libnwam_backend.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["218853083100286637199120867932228037110","168826584985958166134520320518583967045","26191290888156789062071679860722285350","245297335228683292275136684542271113000","303641728039117508436397784663510303384","35961221557737378441915234848588201808","273719354646496836412695803191063894393","2645907667212540345052678874851484334"]},"id":"CVE-2026-104114-e6366f6b","signature_type":"Line"},{"deprecated":false,"digest":{"length":1880,"function_hash":"37413150172537493155664129059848167143"},"id":"CVE-2026-104114-f4a54c47","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0","target":{"file":"usr/src/cmd/cmd-inet/lib/nwamd/door_if.c","function":"nwamd_door_switch"}}],"vanir_signatures_modified":"2026-10-10T07:06:14Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104114.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"}]}