Description
A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
Published: 2026-10-09
Score: 6.8 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update your illumos distribution to one that includes the fix for this issue.


Vendor Workaround

One can mitigate by disabling the name-service-cache SMF service in every affected zone, but once upgraded that service should be re-enabled.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Illumos
Illumos illumos-gate
Omnios
Omnios omnios
Vendors & Products Illumos
Illumos illumos-gate
Omnios
Omnios omnios

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
Title Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory
Weaknesses CWE-772
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P'}


Subscriptions

Illumos Illumos-gate
Omnios Omnios
cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T16:45:36.172Z

Reserved: 2026-10-01T18:07:53.956Z

Link: CVE-2026-104112

cve-icon Vulnrichment

Updated: 2026-10-09T16:15:18.920Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:07.100

Modified: 2026-10-09T17:16:44.340

Link: CVE-2026-104112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T15:45:07Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime