A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
{
"cna_assigner": "illumos",
"cwe_ids": [
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104114.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "r151058"
},
{
"fixed": "r151058w"
},
{
"introduced": "r151056"
},
{
"fixed": "r151056aw"
},
{
"introduced": "r151054"
},
{
"fixed": "r151054bw"
},
{
"introduced": "any"
},
{
"fixed": "r151054"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104114.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "182257522554449769069343743966968080892",
"length": 2793
},
"id": "CVE-2026-104114-8758d4ee",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0",
"target": {
"file": "usr/src/lib/libnwam/common/libnwam_backend.c",
"function": "nwam_backend_door_server"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"186332791323576956723887412042360141499",
"254424715392401920924313611307373415623",
"6771889911526717672553369584756059091",
"265248265874785983907488398052940856246"
],
"threshold": 0.9
},
"id": "CVE-2026-104114-a5a15cbd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0",
"target": {
"file": "usr/src/cmd/cmd-inet/lib/nwamd/door_if.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"218853083100286637199120867932228037110",
"168826584985958166134520320518583967045",
"26191290888156789062071679860722285350",
"245297335228683292275136684542271113000",
"303641728039117508436397784663510303384",
"35961221557737378441915234848588201808",
"273719354646496836412695803191063894393",
"2645907667212540345052678874851484334"
],
"threshold": 0.9
},
"id": "CVE-2026-104114-e6366f6b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0",
"target": {
"file": "usr/src/lib/libnwam/common/libnwam_backend.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "37413150172537493155664129059848167143",
"length": 1880
},
"id": "CVE-2026-104114-f4a54c47",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0",
"target": {
"file": "usr/src/cmd/cmd-inet/lib/nwamd/door_if.c",
"function": "nwamd_door_switch"
}
}
]
"2026-10-10T07:06:14Z"