Executive brief
A vulnerability in the Oracle Solaris operating system's filesystem component allows a user with low-level access to disrupt the entire system. An attacker can exploit this flaw to cause the server to hang or crash repeatedly, leading to a total loss of service availability. This could impact business operations by forcing downtime on critical infrastructure running Solaris 11.4.
Technical details
A vulnerability exists in the Filesystems component of Oracle Solaris version 11.4. The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials with low privileges. By exploiting this issue, an attacker can trigger a complete denial-of-service (DoS) condition, manifested as a system hang or a frequently repeatable crash. The vulnerability has a CVSS 3.1 base score of 5.5, reflecting a high impact on availability but no impact on confidentiality or integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle Solaris 11.4
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.
- 2026-07-21: advisory: Included in the Oracle Critical Patch Update (CPU).