CVE-2026-104112 illumos nscd 资源耗尽拒绝服务漏洞
影响本地非特权用户可耗尽内核内存,导致主机所有区域进程无响应
illumos 名称服务缓存守护进程 nscd 的 door 服务过程 switcher() 未关闭随 door 调用传入但未被请求使用的文件描述符。由于 nscd 以无限制文件描述符上限运行,且 /var/run/name_service_door 接受本区域任意用户传入的描述符,本地非特权用户可反复传入描述符使 nscd 的文件描述符表在内核内存中无限增长。该缺陷自 2006 年起存在,影响 illumos-gate commit af810a72 之前的所有 illumos 发行版。
影响范围
所有 illumos 发行版,版本早于 illumos-gate commit af810a72;具体发行版版本号暂无公开信息。
漏洞详情
漏洞类型为资源未释放(CWE-404)导致的拒绝服务。nscd 的 door 服务过程 switcher() 在处理 door_call 时,对调用方传入但请求本身不使用的文件描述符未执行关闭操作,造成文件描述符泄漏。由于 nscd 运行于无限制文件描述符上限,且其主 door 接受同区域任意用户传入的描述符,非特权本地用户(包括非全局区域内的用户)可通过循环调用 door_call() 持续传入描述符,使 nscd 的文件描述符表在内核内存中不断膨胀。
利用条件与风险
利用前提是攻击者能在目标主机某区域(含非全局区域)内以任意本地用户身份执行代码并访问 /var/run/name_service_door。实战中可导致 nscd 拒绝服务,并波及主机上所有区域的进程,造成整机不可用。
修复建议
官方修复方案为升级至 illumos-gate commit af810a72 或之后版本,该提交修复了 switcher() 中文件描述符未关闭的问题。临时缓解措施暂无公开信息,可考虑限制本地用户访问 nscd door 或对 nscd 设置文件描述符上限。
A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone’s nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.