FD leak in illumos nscd allows local kernel memory exhaustion
CVSS 4.0
6.8medium
EPSS
—
Published
()
Modified
AI analysis
The illumos name service cache daemon (nscd) does not release file descriptors that a door client passes but the request does not use. switcher() in usr/src/cmd/nscd/nscd_frontend.c leaves those descriptors open, and the main door at /var/run/name_service_door accepts them from any user in the zone. An unprivileged local user, including one in a non-global zone, can loop door_call() and pass descriptors so nscd's unlimited file-descriptor table grows without bound in kernel memory. That denies service to nscd and can make processes in every zone on the host unresponsive. The bug has existed since 2006 and affects every illumos distribution before illumos-gate commit af810a72; no public proof-of-concept is known and it is not in the CISA KEV catalog.
What to do: Install an illumos build that includes illumos-gate commit af810a72 (or a distribution package that backports it) and restart nscd. Until then, restrict local and non-global-zone logins that can call the name-service door, and watch nscd's open file-descriptor count and kernel memory; restarting nscd frees leaked descriptors but does not fix the leak.
Affected
illumos nscd (name service cache daemon)
Any illumos distribution before illumos-gate commit af810a72 (present since commit cb5caa98 in 2006)
Estimated exposure
nichelow thousands of hosts (order-of-magnitude estimate; illumos-family systems) — No install counts or public scan totals are in the data; the estimate is from illumos being a niche OpenSolaris-derived OS (OpenIndiana, OmniOS, SmartOS and similar) with far smaller deployment than mainstream Linux.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
illumos reported door-server CVEs causing denial of service and missing authorization in nscd and ipmgmtd.
Dan McDonald reported illumos CVEs for denial of service and missing authorization in door server processes, spanning CVE-2026-104112 through CVE-2026-104117. CVE-2026-104112 (bug 18494) is unbounded file-descriptor allocation in nscd. CVE-2026-104113 is an ipmgmtd double-free of caller credentials on authorization failure, limited to OmniOS and SmartOS rather than general illumos. No active exploitation is stated.