CVE-2026-15449

MEDIUM

TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption

Title source: cna
STIX 2.1

Description

A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_ioc_prop_common() in usr/src/uts/common/io/dld/dld_drv.c copies the dld_ioc_macprop_t ioctl header in once to read its pr_valsize field, sizes and allocates a kernel heap buffer from that value, and then copies the full request in a second time from the same unprivileged user address. A concurrent thread can enlarge pr_valsize between the two copyins, so the second copyin and the subsequent property handling write beyond the end of the undersized allocation and corrupt the kernel heap. An unprivileged local user, including one confined to a non-global zone that owns a datalink, can trigger this to panic the system. The resulting kernel heap corruption may be usable for further compromise.

Scores

CVSS v4 5.8
EPSS 0.0008
EPSS Percentile 0.4%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-122 CWE-367
Status published
Products (6)
illumos/illumos-gate eae72b5b807baa9116e64502cbb278edf15f3146 - 6959feb5b430411a4809b06c53dcdb42fb525eac
OmniOS/OmniOS any - r151054
OmniOS/OmniOS r151054 - r151054bj
OmniOS/OmniOS r151056 - r151056aj
OmniOS/OmniOS r151058 - r151058j
Triton Data Center/SmartOS any - 202060709
Published Jul 16, 2026
Tracked Since Jul 17, 2026