CVE-2026-104117 illumos ipmgmtd 缺失授权检查漏洞
影响本地普通用户可篡改持久化 IPMP 配置,重启后可能中断网络连接
illumos 的 IP 管理守护进程 ipmgmtd 在处理 IPMGMT_CMD_IPMP_UPDATE 命令时缺少 solaris.network.interface.config 授权检查。该命令的处理函数在设置 IPMGMT_PERSIST 标志时会写入持久化的 ipadm 配置。因此本地非特权用户可修改已存储的 IPMP 组配置。
影响范围
影响 illumos-gate commit a73be61a(2021 年引入)之后、commit e8d3efa1 之前的所有 illumos 发行版。具体发行版版本号暂无公开信息。
漏洞详情
漏洞类型为缺失授权检查(CWE-862)。ipmgmtd 的 door 分发表未对 IPMGMT_CMD_IPMP_UPDATE 命令要求相应授权,而其处理函数 ipmgmt_ipmp_update_handler() 在持久化标志置位时会写入 ipadm 持久配置。攻击者借此可向现有 IPMP 组添加或移除接口,但仅影响存储配置,运行配置不变,需在下次应用(如重启)时生效。
利用条件与风险
利用前提是攻击者拥有本地非特权账户访问权限。实战中可导致持久化网络配置被篡改,重启后 IPMP 组配置异常,可能造成网络中断或流量走向改变。
修复建议
升级至 illumos-gate commit e8d3efa1 或之后版本以修复。临时缓解措施暂无公开信息,可考虑限制本地非特权用户访问 ipmgmtd door 接口。
A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.