{"id":"CVE-2026-104115","summary":"Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon","details":"A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.","modified":"2026-10-10T07:06:16.588185568Z","published":"2026-10-09T14:24:52.028Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104115.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"r151058"},{"fixed":"r151058w"},{"introduced":"r151056"},{"fixed":"r151056aw"},{"introduced":"r151054"},{"fixed":"r151054bw"},{"introduced":"any"},{"fixed":"r151054"}]}],"cna_assigner":"illumos","cwe_ids":["CWE-121"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104115.json"},{"type":"PACKAGE","url":"https://github.com/illumos/illumos-gate"},{"type":"FIX","url":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35"},{"type":"WEB","url":"https://illumos.org"},{"type":"REPORT","url":"https://illumos.org/issues/18496"},{"type":"ARTICLE","url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104115"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/illumos/illumos-gate","events":[{"introduced":"2f172c55ef76964744bc62b4500ece87f3089b4d"},{"fixed":"6a2df4aa5381599179ab6afb3165db81960dee35"}]}],"database_specific":{"vanir_signatures_modified":"2026-10-10T07:06:16Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104115.json","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["124566200494059636592528346457473752035","54573476237393821346774256133544509146","32236614940780802387322228558796431268","135978244609392853535369683172384619572","244818822112230700546138714082126995819"]},"id":"CVE-2026-104115-6747ea12","signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35","target":{"file":"usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35","target":{"file":"usr/src/cmd/fs.d/reparsed/reparsed.c"},"deprecated":false,"digest":{"line_hashes":["219707144087167172533659582027846905508","220197857703079431387417038044421024396","166585396280267872327470956086444313611","114588790152156330099303875038997675004","37277729827977880409871169956915303495","223697067479106890925435216257878641953","337076642651596631308167365203275157399","307436016302591702808640572103891593924","69187773704557674943286844249929907652","127161729362659692974694111600214930772","166056894342475810946448172811880883817","160872293436155669314984852056998516415","58573055402481028301542922718907846549","138883665139597461241655108020657636496","96559753014931736509536996038929373778","295150196444236424086628772975061227679","330843659200281347069004494004871624393","89000888574861658990443847519922466271","189792405876485234820680438476779582698"],"threshold":0.9},"id":"CVE-2026-104115-77a58e16"},{"target":{"file":"usr/src/cmd/fs.d/reparsed/reparsed.c","function":"reparsed_doorfunc"},"deprecated":false,"digest":{"length":1531,"function_hash":"333998636057054084261394455486497693815"},"id":"CVE-2026-104115-99070e96","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35"},{"digest":{"function_hash":"219118797551256176449295008495304642342","length":746},"id":"CVE-2026-104115-a3164df7","signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35","target":{"function":"start_reparsed_svcs","file":"usr/src/cmd/fs.d/reparsed/reparsed.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35","target":{"file":"usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c","function":"get_fs_locations"},"deprecated":false,"digest":{"function_hash":"83676391679187376632543437724540513791","length":2687},"id":"CVE-2026-104115-fc3b3b88"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"}]}