天下漏洞,尽知其名
MEDIUM

CVE-2026-104115 illumos reparsed 栈缓冲区溢出漏洞

影响本地非特权用户可导致 reparsed 守护进程崩溃并进入维护状态

MEDIUM
暂无 CVSS 评分
AI 研判

illumos 的 reparse point 守护进程 reparsed 中,nfs-basic 插件的 get_fs_locations() 函数在将 reparse 字符串的主机名和路径组件复制到固定 1024 字节栈缓冲区时未做长度检查,存在栈缓冲区溢出。该漏洞自 2009 年起存在,影响 illumos-gate commit 6a2df4aa 之前的所有 illumos 发行版。

影响范围

illumos

illumos-gate commit 6a2df4aa 之前的所有 illumos 发行版;具体受影响发行版与版本号暂无公开信息。

漏洞详情

漏洞类型为栈缓冲区溢出(CWE-121)。reparsed 的 door 文件 /var/run/reparsed_door 对所有用户可读,且 door 服务端不校验调用者凭据,本地非特权用户可发送带有超长 host 或 path 组件的 nfs-basic 请求触发溢出。在默认启用栈保护的系统中,溢出会导致 reparsed 中止,反复请求会使 svc:/system/filesystem/reparse 服务进入维护状态。

利用条件与风险

利用前提是本地非特权用户可访问 reparsed door 且目标系统启用了 reparse 服务(该服务默认禁用)。实战风险以拒绝服务为主,可导致守护进程崩溃及服务进入维护状态,暂未发现远程代码执行或权限提升的公开证据。

修复建议

官方修复方案为升级至 illumos-gate commit 6a2df4aa 或更高版本。临时缓解措施包括禁用 svc:/system/filesystem/reparse 服务(默认已禁用),或限制对 /var/run/reparsed_door 的访问;具体补丁细节以 illumos 官方公告为准。

原始情报

A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller’s credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.