AI analysis
A missing authorization check in the illumos IP management daemon (ipmgmtd) lets an unprivileged local user change the persistent IP multipathing (IPMP) configuration. The door dispatch path for IPMGMT_CMD_IPMP_UPDATE does not require the solaris.network.interface.config authorization, so ipmgmt_ipmp_update_handler() can write the stored ipadm configuration when the IPMGMT_PERSIST flag is set and add interfaces to, or remove them from, existing IPMP groups. The running configuration is not changed immediately; the altered stored config is applied later, such as at boot, and can disrupt network connectivity. The bug has been present since illumos-gate commit a73be61a in 2021 and affects any illumos distribution built before commit e8d3efa1. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Update any illumos-based system to a build that includes illumos-gate commit e8d3efa1 or later, using the fixed packages from your distribution (OpenIndiana, OmniOS, SmartOS, and others track illumos-gate separately; no single version number is given). Until then, limit local unprivileged accounts and review stored ipadm/IPMP configuration for unexpected interface membership before the next reboot or config apply.
Affected
| illumos (ipmgmtd / illumos-gate) | All illumos distributions built before illumos-gate commit e8d3efa1; flaw present since commit a73be61a (2021) |
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.