Impact
A flaw in the Oracle Solaris kernel allows a low‑privileged local user to trigger an unrecoverable crash, causing the operating system to hang or stop responding. The vulnerability does not compromise confidentiality or integrity, but it can make the entire system unavailable until it is restarted. It is classified as a local denial of service attack.
Affected Systems
Oracle Solaris version 11.4 is affected. The flaw resides in the kernel component and can impact other Oracle products that run on the same infrastructure due to scope change.
Risk and Exploitability
The CVSS 3.1 score of 6.5 indicates moderate severity. The EPSS score of <1% shows a very low probability of exploitation in the wild, but because the flaw can be triggered with local logon and low privileges, environments where users have unsecured access remain at risk. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local exploitation by a non‑administrator user who can execute code with sufficient privilege to manipulate kernel memory, potentially causing the system to hang or crash.
OpenCVE Enrichment