A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.
{
"cna_assigner": "illumos",
"cwe_ids": [
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104115.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "r151058"
},
{
"fixed": "r151058w"
},
{
"introduced": "r151056"
},
{
"fixed": "r151056aw"
},
{
"introduced": "r151054"
},
{
"fixed": "r151054bw"
},
{
"introduced": "any"
},
{
"fixed": "r151054"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104115.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"124566200494059636592528346457473752035",
"54573476237393821346774256133544509146",
"32236614940780802387322228558796431268",
"135978244609392853535369683172384619572",
"244818822112230700546138714082126995819"
],
"threshold": 0.9
},
"id": "CVE-2026-104115-6747ea12",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
"target": {
"file": "usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"219707144087167172533659582027846905508",
"220197857703079431387417038044421024396",
"166585396280267872327470956086444313611",
"114588790152156330099303875038997675004",
"37277729827977880409871169956915303495",
"223697067479106890925435216257878641953",
"337076642651596631308167365203275157399",
"307436016302591702808640572103891593924",
"69187773704557674943286844249929907652",
"127161729362659692974694111600214930772",
"166056894342475810946448172811880883817",
"160872293436155669314984852056998516415",
"58573055402481028301542922718907846549",
"138883665139597461241655108020657636496",
"96559753014931736509536996038929373778",
"295150196444236424086628772975061227679",
"330843659200281347069004494004871624393",
"89000888574861658990443847519922466271",
"189792405876485234820680438476779582698"
],
"threshold": 0.9
},
"id": "CVE-2026-104115-77a58e16",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
"target": {
"file": "usr/src/cmd/fs.d/reparsed/reparsed.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "333998636057054084261394455486497693815",
"length": 1531
},
"id": "CVE-2026-104115-99070e96",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
"target": {
"file": "usr/src/cmd/fs.d/reparsed/reparsed.c",
"function": "reparsed_doorfunc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "219118797551256176449295008495304642342",
"length": 746
},
"id": "CVE-2026-104115-a3164df7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
"target": {
"file": "usr/src/cmd/fs.d/reparsed/reparsed.c",
"function": "start_reparsed_svcs"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "83676391679187376632543437724540513791",
"length": 2687
},
"id": "CVE-2026-104115-fc3b3b88",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
"target": {
"file": "usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c",
"function": "get_fs_locations"
}
}
]
"2026-10-10T07:06:16Z"