CVE-2026-104115

Source
https://cve.org/CVERecord?id=CVE-2026-104115
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104115.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104115
Published
2026-10-09T14:24:52Z
Modified
2026-10-10T07:06:16Z
Severity
  • 5.4 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the daemon
Details

A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.

Database specific
{
    "cna_assigner": "illumos",
    "cwe_ids": [
        "CWE-121"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104115.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "r151058"
                },
                {
                    "fixed": "r151058w"
                },
                {
                    "introduced": "r151056"
                },
                {
                    "fixed": "r151056aw"
                },
                {
                    "introduced": "r151054"
                },
                {
                    "fixed": "r151054bw"
                },
                {
                    "introduced": "any"
                },
                {
                    "fixed": "r151054"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/illumos/illumos-gate

Affected ranges

Type
GIT
Repo
https://github.com/illumos/illumos-gate
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104115.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "124566200494059636592528346457473752035",
                "54573476237393821346774256133544509146",
                "32236614940780802387322228558796431268",
                "135978244609392853535369683172384619572",
                "244818822112230700546138714082126995819"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-104115-6747ea12",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
        "target": {
            "file": "usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "219707144087167172533659582027846905508",
                "220197857703079431387417038044421024396",
                "166585396280267872327470956086444313611",
                "114588790152156330099303875038997675004",
                "37277729827977880409871169956915303495",
                "223697067479106890925435216257878641953",
                "337076642651596631308167365203275157399",
                "307436016302591702808640572103891593924",
                "69187773704557674943286844249929907652",
                "127161729362659692974694111600214930772",
                "166056894342475810946448172811880883817",
                "160872293436155669314984852056998516415",
                "58573055402481028301542922718907846549",
                "138883665139597461241655108020657636496",
                "96559753014931736509536996038929373778",
                "295150196444236424086628772975061227679",
                "330843659200281347069004494004871624393",
                "89000888574861658990443847519922466271",
                "189792405876485234820680438476779582698"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-104115-77a58e16",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
        "target": {
            "file": "usr/src/cmd/fs.d/reparsed/reparsed.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "333998636057054084261394455486497693815",
            "length": 1531
        },
        "id": "CVE-2026-104115-99070e96",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
        "target": {
            "file": "usr/src/cmd/fs.d/reparsed/reparsed.c",
            "function": "reparsed_doorfunc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "219118797551256176449295008495304642342",
            "length": 746
        },
        "id": "CVE-2026-104115-a3164df7",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
        "target": {
            "file": "usr/src/cmd/fs.d/reparsed/reparsed.c",
            "function": "start_reparsed_svcs"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "83676391679187376632543437724540513791",
            "length": 2687
        },
        "id": "CVE-2026-104115-fc3b3b88",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35",
        "target": {
            "file": "usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c",
            "function": "get_fs_locations"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:06:16Z"