A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.

Project Subscriptions

Vendors Products
Illumos Subscribe
Illumos-gate Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update your illumos distribution to one that includes the fix for this issue.


Workaround

One can mitigate by disabling the name-service-cache SMF service in every affected zone, but once upgraded that service should be re-enabled.

History

Fri, 09 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Illumos
Illumos illumos-gate
Omnios
Omnios omnios
Vendors & Products Illumos
Illumos illumos-gate
Omnios
Omnios omnios

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
Title Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory
Weaknesses CWE-772
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T16:45:36.172Z

Reserved: 2026-10-01T18:07:53.956Z

Link: CVE-2026-104112

cve-icon Vulnrichment

Updated: 2026-10-09T16:15:18.920Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:07.100

Modified: 2026-10-09T17:16:44.340

Link: CVE-2026-104112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T15:45:07Z

Weaknesses