CVE-2026-104115: Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon
A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. getfslocations() in usr/src/cmd/fs.d/nfs/rpbasic/libnfsbasic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparseddoor is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
illumosto a version that resolves this vulnerability.Patch 6a2df4aa
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems are exposed if the reparse service is enabled and they use an illumos build prior to illumos-gate commit 6a2df4aa. The affected nfs-basic plugin has been present since 2009; the service is disabled by default.
What access does an attacker need?
An attacker needs local access only. Any unprivileged local user can read /var/run/reparsed_door and submit an nfs-basic request because the door server does not validate caller credentials.
What is the practical impact on systems with default stack protection?
An overlong host or path component causes reparsed to abort. Repeating the request can place svc:/system/filesystem/reparse into maintenance, resulting in denial of service.
What can be done before applying the fix?
Keep the reparse service disabled if it is not required. If it must be enabled, limit untrusted local access because the door is readable by all users and caller credentials are not checked.