Impact
A flaw in the filesystems component of Oracle Solaris allows a local attacker who possesses logon credentials and low privileges to force the operating system to hang or repeatedly crash. The vulnerability is exploitable without user interaction and directly impacts availability, terminating user sessions, stopping services, or requiring a reboot. The description indicates that the flaw is tied to filesystem operations, and it is inferred that this involves improper handling of those operations, which can lead to a complete denial of service.
Affected Systems
Oracle Solaris version 11.4 is affected by this issue; the vulnerability applies to any installation that has not applied the Oracle patch released in the July 2026 Critical Patch Update.
Risk and Exploitability
The CVSS v3.1 base score of 5.5 denotes a moderate severity, and the EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Its local attack vector and low privilege requirements mean that only users with logon access to the system can leverage the flaw; the impact is isolated to availability of the affected Solaris instance.
OpenCVE Enrichment