On 9 October 2026, Dan McDonald posted an illumos advisory on the oss-sec list about multiple CVEs in door servers. According to the available text, the list includes CVE-2026-104112, related to unbounded file descriptor allocation in nscd, and CVE-2026-104113, in which ipmgmtd frees the requester's credentials twice when an authorization failure occurs. The advisory states that CVE-2026-104113 affects only OmniOS and SmartOS and is not a general illumos problem. The content was machine-translated, and the text received contains no further details on affected versions or fixes. To consult the original, open the 2026 oss-sec archive, section q4, at the address given in the source, and check the illumos project message in the developer group. Before acting, verify the official CVE list and your distribution's release notes.
Cyber ·
Multiple CVEs for illumos and distributions: door server processes
The illumos project disclosed multiple CVEs affecting door servers, including unbounded file descriptor allocation and authorization flaws. This record gathers the facts published on the oss-sec list on 9 October 2026.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.