Multiple CVEs for illumos and distros: door server processes
illumos reported door-server CVEs causing denial of service and missing authorization in nscd and ipmgmtd.
Dan McDonald reported illumos CVEs for denial of service and missing authorization in door server processes, spanning CVE-2026-104112 through CVE-2026-104117. CVE-2026-104112 (bug 18494) is unbounded file-descriptor allocation in nscd. CVE-2026-104113 is an ipmgmtd double-free of caller credentials on authorization failure, limited to OmniOS and SmartOS rather than general illumos. No active exploitation is stated.
40