[oi-dev] [developer] [CVE-2026-35384] 18003 poll(4D) needs to better-check numfds
Lionel Cons
lionelcons1972 at gmail.com
Thu Jul 9 09:18:00 UTC 2026
On Wed, 8 Jul 2026 at 21:02, Dan McDonald <danmcd at edgecast.io> wrote:
>
> Hi folks,
>
> illumos#18003 fixes a serious kernel heap corruption in poll(4D) that has
> been in illumos since 2015. When properly exploited (which is thankfully
> difficult), a user at non-global-zone process can escalate its privilege to
> root at global-zone, or myriad other kernel-heap-writing opportunities.
>
> Distributions should treat this as a high-priority update. Anyone running
> on systems where untrusted local users, or zone tenants, can execute code
> should be especially attentive.
>
>
> IMPACT: An unprivileged user can induce kernel heap corruption without much
> effort. A well-informed/highly-skilled unprivileged user can target kernel
> heap changes such that it can result in privilege escalation.
>
> The unprivileged user can be in any zone that allows native illumos process
> execution. HVM zones (such as BHYVE ones) are only vulnerable only after a
> hypervisor escape. Even in native or LX zones, privilege escalation requires
> boot-time knowledge specific data-structure layouts and locations.
>
>
> ACTION: Please be on the look out for distributions updates: either patches
> or full releases. If you cannot update immediately, there is a potential
> mitigation available.
>
>
> MTIGATION: At a performance cost, the following mitigation, applied using
> root at global-zone, can stop the attack. The mitigation only lasts the lifetime
> of the boot. We highly recommend updating as soon as possible.
When will the next openindiana release (including NFSv4.1 patches)
with this fix be available?
Lionel
More information about the oi-dev
mailing list