CVE-2026-15449

Source
https://cve.org/CVERecord?id=CVE-2026-15449
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15449.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15449
Published
2026-07-16T19:27:16.036Z
Modified
2026-07-31T08:04:16.063209Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption
Details

A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOCGETMACPROP and DLDIOCSETMACPROP ioctls on /dev/dld. drviocpropcommon() in usr/src/uts/common/io/dld/dlddrv.c copies the dldiocmacpropt ioctl header in once to read its prvalsize field, sizes and allocates a kernel heap buffer from that value, and then copies the full request in a second time from the same unprivileged user address. A concurrent thread can enlarge pr_valsize between the two copyins, so the second copyin and the subsequent property handling write beyond the end of the undersized allocation and corrupt the kernel heap. An unprivileged local user, including one confined to a non-global zone that owns a datalink, can trigger this to panic the system. The resulting kernel heap corruption may be usable for further compromise.

Database specific
{
    "cwe_ids": [
        "CWE-122",
        "CWE-367"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15449.json",
    "cna_assigner": "illumos",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "eae72b5b807baa9116e64502cbb278edf15f3146"
                },
                {
                    "fixed": "6959feb5b430411a4809b06c53dcdb42fb525eac"
                },
                {
                    "introduced": "any"
                },
                {
                    "fixed": "r151054"
                },
                {
                    "introduced": "r151058"
                },
                {
                    "fixed": "r151058j"
                },
                {
                    "introduced": "r151056"
                },
                {
                    "fixed": "r151056aj"
                },
                {
                    "introduced": "r151054"
                },
                {
                    "fixed": "r151054bj"
                },
                {
                    "introduced": "any"
                },
                {
                    "fixed": "202060709"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/illumos/illumos-gate

Affected ranges

Type
GIT
Repo
https://github.com/illumos/illumos-gate
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

vanir_signatures_modified
"2026-07-31T08:04:16Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "usr/src/uts/common/sys/dld.h"
        },
        "deprecated": false,
        "source": "https://github.com/illumos/illumos-gate/commit/6959feb5b430411a4809b06c53dcdb42fb525eac",
        "id": "CVE-2026-15449-25ae39b0",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "55265583385496202335914314670570819907",
                "221063065831643637390214237659649581409",
                "271983323205171776377956030116550307586",
                "24127235828013299269471911354824813126",
                "280224035377878154423169344147211206865",
                "190398630160561989033252967705125301035",
                "249717396117762287019750488471903216184"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "usr/src/lib/libdladm/common/linkprop.c"
        },
        "deprecated": false,
        "source": "https://github.com/illumos/illumos-gate/commit/6959feb5b430411a4809b06c53dcdb42fb525eac",
        "id": "CVE-2026-15449-29393f7d",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "204543742974103374691670753818357608581",
                "247486358090974245053435658663199818565",
                "90099904100560373005206421624631205042",
                "332365739118138598947675965209200172734",
                "19074404445857062408948632541682930739",
                "57797682565361751982497551977559899673",
                "145791412351482786174454040485760845331",
                "105146608967100863941777736353445906844"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "usr/src/uts/common/io/dld/dld_drv.c",
            "function": "drv_ioc_prop_common"
        },
        "deprecated": false,
        "source": "https://github.com/illumos/illumos-gate/commit/6959feb5b430411a4809b06c53dcdb42fb525eac",
        "id": "CVE-2026-15449-be3a3e9b",
        "signature_version": "v1",
        "digest": {
            "function_hash": "113716015201161947114602798910962094905",
            "length": 3411.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "usr/src/uts/common/io/dld/dld_drv.c"
        },
        "deprecated": false,
        "source": "https://github.com/illumos/illumos-gate/commit/6959feb5b430411a4809b06c53dcdb42fb525eac",
        "id": "CVE-2026-15449-ece4e9a6",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "16732121964487752892890219027212272968",
                "92257841827269794426200720105329009303",
                "147216997403623721152208155866538539860",
                "36765103303041988163726411456029641363",
                "202908176228535953613110081379210733586",
                "41544739674699448879043952395334131320",
                "183699307696834386157549923791530873947",
                "29308563573312750428456024476119155549",
                "48216052754832808099803659167806927052",
                "335948185273294377358543821418286544386"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15449.json"