CVE-2026-104114 illumos nwamd 空指针解引用漏洞
影响本地非特权用户可崩溃 nwamd 守护进程,导致网络自动配置服务中断
illumos 的 Network Auto-Magic 守护进程 nwamd 在 door_if.c 的 nwamd_door_switch() 函数中,未先校验请求数据是否存在、也未校验调用者凭据,就直接写入调用者的请求结构,导致空指针解引用。由于 nwam_door 对所有本地用户可访问,非特权用户可借此使 nwamd 崩溃。该缺陷自 2010 年起存在,影响 illumos-gate commit 0f1064d9 之前的所有 illumos 发行版。
影响范围
illumos-gate commit 0f1064d9 之前的所有 illumos 发行版;仅当 svc:/network/physical:nwam 服务启用时受影响(该服务非默认启用)。
漏洞详情
漏洞类型为空指针解引用(CWE-476)。成因是 nwamd_door_switch() 在确认请求参数存在及调用者凭据之前,就向调用者请求结构写入数据。利用方式是本地非特权用户通过 /etc/svc/volatile/nwam/nwam_door 发起不带参数数据的 door_call(),触发空指针解引用使 nwamd 崩溃;重复调用会使 svc:/network/physical:nwam 进入维护状态,停止自动网络配置。
利用条件与风险
利用前提是目标系统启用了 svc:/network/physical:nwam 服务且攻击者拥有本地账户;成功利用仅造成拒绝服务(守护进程崩溃、网络自动配置停止),不涉及权限提升或代码执行。
修复建议
升级至 illumos-gate commit 0f1064d9 或更高版本以修复该缺陷。临时缓解措施为禁用 svc:/network/physical:nwam 服务(若业务允许),或限制本地用户对 nwam_door 的访问。
A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller’s request structure before checking that a request was supplied, and before checking the caller’s credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.