Impact
A flaw in the Oracle Solaris kernel allows a low‑privileged local user to trigger an unrecoverable crash, causing the operating system to hang or stop responding. The vulnerability does not compromise confidentiality or integrity, but it can make the entire system unavailable until it is restarted. It is classified as a local denial of service attack.
Affected Systems
Oracle Solaris version 11.4 is affected. The flaw resides in the kernel component and can impact other Oracle products that run on the same infrastructure due to scope change.
Risk and Exploitability
The CVSS 3.1 score of 6.5 indicates moderate severity. Because the attack requires local logon and is easily exploitable, the likelihood of abuse is high in environments where users have unsecured privileges. The vulnerability is not listed in CISA KEV, and an EPSS score is not available, which suggests no current widespread exploitation has been reported. The likely attack vector is local exploitation by a non‑administrator user who can execute code with sufficient privilege to access kernel memory.
OpenCVE Enrichment