CVE-2026-104114: NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon
A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamddoorswitch() in usr/src/cmd/cmd-inet/lib/nwamd/doorif.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwamdoor is accessible to all local users, an unprivileged user can issue a doorcall() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
illumos-gateto a version that resolves this vulnerability.Patch 0f1064d9