A double-free (CWE-415) in the IP management daemon ipmgmtd on OmniOS and SmartOS lets an unprivileged local user crash the daemon. When a door request that changes interface configuration is processed, ipmgmt_handler() frees the caller's credential with ucred_free() immediately after reading the user ID, then frees it again on the error path if the caller lacks solaris.network.interface.config (for example an IPMGMT_CMD_RESETIF request). The abort can be repeated until svc:/network/ip-interface-management goes to maintenance, blocking IP interface configuration; there is no confidentiality or integrity impact (CVSS 4.0 5.4). The early free was added in 2014 for lx-branded zones (OmniOS commit 4c170900) and is absent from upstream illumos-gate, so OmniOS r151020 and later and SmartOS builds before the fix are affected. No public proof of concept is listed and the issue is not in CISA KEV, although the CVSS vector marks exploit maturity as E:P.
What to do: Install the OmniOS and SmartOS updates that remove the extra ucred_free() in ipmgmtd; the advisory does not name a fixed build, so confirm the fix is in the release you deploy. Upstream illumos-gate is not affected. Until patched, limit unprivileged local accounts and alert if svc:/network/ip-interface-management enters maintenance.
Affected
OmniOS
r151020 and later, prior to the fix
Joyent SmartOS
versions prior to the fix (not present in upstream illumos-gate)
Estimated exposure
nichelow thousands of specialized servers (order-of-magnitude estimate) — OmniOS and SmartOS are niche illumos distributions used mainly for storage, zones, and Triton-style clouds; no active-install counts or public scan totals were provided, so the figure is an order-of-magnitude inference from that limited…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.
illumos reported door-server CVEs causing denial of service and missing authorization in nscd and ipmgmtd.
Dan McDonald reported illumos CVEs for denial of service and missing authorization in door server processes, spanning CVE-2026-104112 through CVE-2026-104117. CVE-2026-104112 (bug 18494) is unbounded file-descriptor allocation in nscd. CVE-2026-104113 is an ipmgmtd double-free of caller credentials on authorization failure, limited to OmniOS and SmartOS rather than general illumos. No active exploitation is stated.