A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
{
"cna_assigner": "illumos",
"cwe_ids": [
"CWE-415"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104113.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "r151058"
},
{
"fixed": "r151058w"
},
{
"introduced": "r151056"
},
{
"fixed": "r151056aw"
},
{
"introduced": "r151054"
},
{
"fixed": "r151054bw"
},
{
"introduced": "r151020"
},
{
"fixed": "r151054"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104113.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"298381756739132767320796100954115260494",
"133019350961963087075150217541824466935",
"324640063200016750816945259360219319187",
"2337954271442398907744236231188024279",
"128787396011463472516764321029087614799",
"273097059712255288959238292389125933310",
"4727405014489457474081475550178203966",
"191244543335672928605256189356186263098"
],
"threshold": 0.9
},
"id": "CVE-2026-104113-a97614f3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/omniosorg/illumos-omnios/commit/670d853f335203ce8a66126cdbb25bfdba973036",
"target": {
"file": "usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "338343569368610172075324576610663289242",
"length": 1345
},
"id": "CVE-2026-104113-c48566aa",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/omniosorg/illumos-omnios/commit/670d853f335203ce8a66126cdbb25bfdba973036",
"target": {
"file": "usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c",
"function": "ipmgmt_handler"
}
}
]
"2026-10-11T07:00:57Z"