illumos discloses door-server CVEs and a bhyve bug
illumos disclosed door-server DoS and authorization CVEs plus a bhyve REP-prefix flag bug, with no exploitation reported.
On 9 October 2026, oss-security carried two separate illumos disclosures. Dan McDonald reported door-server issues spanning CVE-2026-104112 through CVE-2026-104117, covering denial of service and missing authorization in nscd and ipmgmtd. CVE-2026-104112 (bug 18494) is unbounded file-descriptor allocation in nscd, while CVE-2026-104113 is an ipmgmtd double-free of caller credentials after an authorization failure and is limited to OmniOS and SmartOS rather than general illumos. Separately, illumos reported CVE-2026-102916 (bug 18491), in which bhyve virtual machine monitor emulation of REP-prefix instructions mishandles CPU flags. Emily Albini of Oxide Computer discovered that flaw and iximeow of Oxide Computer fixed it. Neither notice describes exploitation, and the reports do not conflict because they cover different components.
- Dan McDonald reported illumos door-server CVEs CVE-2026-104112 through CVE-2026-104117 covering denial of service and missing authorization.
- CVE-2026-104112 (bug 18494) is unbounded file-descriptor allocation in nscd.
- CVE-2026-104113 is an ipmgmtd double-free of caller credentials after authorization failure, limited to OmniOS and SmartOS rather than general illumos.
- CVE-2026-102916 (illumos bug 18491) is a bhyve VMM flaw in which REP-prefix instruction emulation mishandles CPU flags.
- Emily Albini of Oxide Computer discovered CVE-2026-102916; iximeow of Oxide Computer fixed it.
- Neither notice states active or in-the-wild exploitation.
- Both oss-security reports are dated 2026-10-09.
Coverage timelineoldest first · each row is one article
- · 23h agoMultiple CVEs for illumos and distros: door server processes
oss-security· 40
illumos reported door-server CVEs causing denial of service and missing authorization in nscd and ipmgmtd.
- · 23h agoCVE for illumos and distros: VMM/BHYVE
oss-security· 42
illumos disclosed CVE-2026-102916, a bhyve REP-prefix emulation bug that mishandles CPU flags.
Vulnerabilities in this storyAll →
- CVE-2026-1029166.8—Guest-triggered host panic in illumos bhyve emulatorpublished · illumos-gate (bhyve / vmm instruction emulator)
- CVE-2026-1041126.8—FD leak in illumos nscd allows local kernel memory exhaustionpublished · illumos nscd (name service cache daemon)