A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamddoorswitch() in usr/src/cmd/cmd-inet/lib/nwamd/doorif.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwamdoor is accessible to all local users, an unprivileged user can issue a doorcall() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
Per https://illumos.topicbox.com/groups/developer/T3b859664594b7762-Maa764f8552227c7080bcaabc/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers illumos would like to report the following CVEs:
CVE-2026-104112 18494 nscd: unbounded file descriptor allocation
CVE-2026-104113 ipmgmtd double-frees caller credentials on authorization failure (OmniOS and SmartOS only, no general illumos issue)
CVE-2026-104114 18495 Empty nwamd Door payload allows Denial of Service
CVE-2026-104115 18496 Unauthenticated Stack Overflow in reparsed
CVE-2026-104116 18493 Missing doorucred Check in zonestatd
CVE-2026-104117 18492 Missing Authorization in ipmgmtd Allows IPMP Reconfiguration
These were all discovered by Robert French and James Wynne III.
Thank you, Dan McDonald, on behalf of illumos security