A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
Advisories

No advisories yet.

Fixes

Solution

Update your illumos distribution to one that includes the fix for this issue.


Workaround

Systems that use the default svc:/network/physical:default service instead of svc:/network/physical:nwam do not run nwamd and are not exposed.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.
Title NULL pointer dereference in illumos nwamd door handler allows local users to crash the daemon
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T14:22:14.611Z

Reserved: 2026-10-01T18:07:53.956Z

Link: CVE-2026-104114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T15:17:07.430

Modified: 2026-10-09T15:17:07.430

Link: CVE-2026-104114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses