天下漏洞,尽知其名
MEDIUM

CVE-2026-104116 illumos zonestatd 权限缺失漏洞

影响本地用户可干扰其他 zone 的 zonestat 并探测运行中的 zone

MEDIUM
暂无 CVSS 评分
AI 研判

illumos 的 zones 统计守护进程 zonestatd 在处理 ZSD_CMD_NEW_ZONE 命令时缺少调用者凭证校验。该命令本应仅由 zoneadmd 发送,但由于 zonestatd 的 door 对所有 zone 中的用户可访问,任意非特权本地用户都能发送该命令。

影响范围

illumos zonestatd

影响 illumos-gate commit 865b58d2 之前的所有 illumos 发行版,该缺陷自 2010 年(commit efd4c9b6)起存在。

漏洞详情

漏洞类型为权限缺失(缺少授权检查)。zonestatd.c 中的 zsd_server() 处理 ZSD_CMD_NEW_ZONE 时未验证调用者身份,攻击者可传入任意 zone ID,使 zonestatd 在该 zone 中重建 door 文件,导致该 zone 新的 zonestat 请求在文件替换期间失败。同时处理命令的耗时差异可被用来判断某 zone ID 是否属于正在运行的 zone。

利用条件与风险

利用前提是攻击者能在任意 zone 内以本地非特权用户身份访问 zonestatd door,实战中可造成跨 zone 的拒绝服务与 zone 运行状态信息泄露,风险等级为中等。

修复建议

官方修复为升级至 illumos-gate commit 865b58d2 或更高版本;临时缓解措施暂无公开信息。

原始情报

A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt zonestat in other zones and to determine which zones are running. The zonestatd door server procedure, zsd_server() in usr/src/cmd/zonestat/zonestatd/zonestatd.c, handles the ZSD_CMD_NEW_ZONE command, which is intended to be sent by zoneadmd, without checking the caller’s credentials. Because the zonestatd door is accessible to all users in every zone, an unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. The time taken to handle the command also reveals whether a given zone ID belongs to a running zone. The flaw has existed since 2010 (illumos-gate commit efd4c9b6), and affects any illumos distribution prior to illumos-gate commit 865b58d2.