CVE-2026-104113, involving ipmgmtd double-freeing caller credentials after an authorization failure, is identified as affecting OmniOS and SmartOS only. The report explicitly says it is not a general illumos issue.
CVE-2026-104115 is described as an unauthenticated stack overflow in reparsed. CVE-2026-104114 also involves an empty nwamd Door payload causing denial of service, but the provided report does not state whether authentication is required.
CVE-2026-104112 allows unbounded file descriptor allocation in nscd, and CVE-2026-104114 allows denial of service through an empty nwamd Door payload. CVE-2026-104115 is an unauthenticated stack overflow in reparsed, which may also present a service risk, although the report does not specify its impact beyond the overflow.
CVE-2026-104116 is a missing door_ucred check in zonestatd. CVE-2026-104117 is missing authorization in ipmgmtd that allows IPMP reconfiguration, while CVE-2026-104113 occurs when ipmgmtd handles an authorization failure.