CVE-2026-104115: Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon

Published Oct 9, 2026
·
Updated

A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. getfslocations() in usr/src/cmd/fs.d/nfs/rpbasic/libnfsbasic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparseddoor is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.

Affected Software

1 affected component
illumos reparsed nfs-basic plugin

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade illumos to a version that resolves this vulnerability.

    Patch 6a2df4aa

Event History

Oct 9, 2026
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems are exposed if the reparse service is enabled and they use an illumos build prior to illumos-gate commit 6a2df4aa. The affected nfs-basic plugin has been present since 2009; the service is disabled by default.

2

What access does an attacker need?

An attacker needs local access only. Any unprivileged local user can read /var/run/reparsed_door and submit an nfs-basic request because the door server does not validate caller credentials.

3

What is the practical impact on systems with default stack protection?

An overlong host or path component causes reparsed to abort. Repeating the request can place svc:/system/filesystem/reparse into maintenance, resulting in denial of service.

4

What can be done before applying the fix?

Keep the reparse service disabled if it is not required. If it must be enabled, limit untrusted local access because the door is readable by all users and caller credentials are not checked.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203