PT-2026-60562 · Omnios+3 · Omnios+2
CVSS v4.0
5.8
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
illumos (affected versions not specified)
Description
A time-of-check to time-of-use (TOCTOU) flaw exists in the data-link pseudo-driver (dld) regarding the handling of
DLDIOC GETMACPROP and DLDIOC SETMACPROP ioctls on the /dev/dld endpoint. The function drv ioc prop common() reads the pr valsize field to allocate a kernel heap buffer and subsequently copies the full request from the same user address. A concurrent thread can modify pr valsize between these two operations, leading to a buffer overflow that corrupts the kernel heap. An unprivileged local user can exploit this to cause a system panic or potentially achieve further system compromise.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Heap Based Buffer Overflow
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Omnios
Smartos
Illumos-Gate