Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update your illumos distribution to one that includes the fix for this issue.
Vendor Workaround
One can mitigate by disabling the name-service-cache SMF service in every affected zone, but once upgraded that service should be re-enabled.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72. | |
| Title | Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory | |
| Weaknesses | CWE-772 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: illumos
Published:
Updated: 2026-10-09T14:23:18.421Z
Reserved: 2026-10-01T18:07:53.956Z
Link: CVE-2026-104112
No data.
Status : Received
Published: 2026-10-09T15:17:07.100
Modified: 2026-10-09T15:17:07.100
Link: CVE-2026-104112
No data.
OpenCVE Enrichment
No data.