CVE-2026-104113 OmniOS/SmartOS ipmgmtd 双重释放漏洞
影响本地非特权用户可致 ipmgmtd 崩溃并进入维护状态,导致 IP 接口无法配置
OmniOS 与 SmartOS 的 IP 管理守护进程 ipmgmtd 存在双重释放漏洞。ipmgmt_handler() 在读取用户 ID 后立即用 ucred_free() 释放调用者凭证,若授权检查失败又在错误路径上再次释放,形成 double free。本地非特权用户可借此使守护进程中止。
影响范围
影响 OmniOS r151020 及之后版本,以及修复前的 SmartOS;该早期释放逻辑由 2014 年支持 lx-branded zones 的提交引入,上游 illumos-gate 不受影响。
漏洞详情
漏洞类型为双重释放(CWE-415)。成因是 ipmgmt_handler() 在读取 UID 后提前释放 ucred 凭证,授权失败的错误路径又重复释放同一凭证。攻击者只需向 ipmgmtd door 发送如 IPMGMT_CMD_RESETIF 的请求即可触发,无需持有 solaris.network.interface.config 授权。
利用条件与风险
利用前提为本地非特权用户可访问 ipmgmtd door,无需特殊权限。成功利用可反复使 ipmgmtd 中止,令 svc:/network/ip-interface-management 服务进入维护状态,造成拒绝服务。
修复建议
建议升级到包含修复的 OmniOS/SmartOS 版本;暂无公开信息说明具体修复补丁编号。临时缓解可限制本地用户对 ipmgmtd door 的访问,或监控并自动重启该服务。
A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller’s credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.