Answer in brief
CVE-2026-104112 records a Medium severity (CVSS 6.8) vulnerability in Missing release of passed file descriptors in illumos nscd allows local users to exhaust kernel memory. The current sources do not mark it as known exploited. The current feed maps OmniOS/OmniOS (generic), illumos/SUNWcs (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps OmniOS/OmniOS (generic), illumos/SUNWcs (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| OmniOS/OmniOSgeneric | >=any <r151054 || >=r151058 <r151058w || >=r151056 <r151056aw || >=r151054 <r151054bw | r151058w, r151056aw, r151054bw |
| illumos/SUNWcsgeneric | >=cb5caa98562cf06753163f558cbcfe30b8f4673a <af810a72c09944e884ec695e8dbf1702a4f424ae | af810a72c09944e884ec695e8dbf1702a4f424ae |
Published upstream
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 9, 2026
A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.
Quoted source text, attributed separately from HOL analysis.