Executive brief
A vulnerability exists in the QNX Neutrino real-time operating system, which is widely used in automotive, medical, and industrial control systems. A local attacker can exploit this flaw to crash the system kernel, leading to a complete loss of availability for the device. This could disrupt critical operations or safety-related functions depending on the specific deployment of the OS.
Technical details
The vulnerability is classified as improper handling of parameters (CWE-233) within the SchedGet() system call of the QNX Neutrino kernel. Due to insufficient validation of input parameters, a local attacker—even without elevated privileges—can invoke the system call in a manner that causes the kernel to crash. This results in a complete denial-of-service (DoS) for the affected system. The issue impacts multiple QNX-based products including the Software Development Platform (SDP), OS for Safety, and OS for Medical. Patches or updates are typically available through BlackBerry's support portal.
Affected products
- BlackBerry QNX Software Development Platform 7.0, 7.1
- BlackBerry QNX OS for Safety 2.0.3 and earlier, 2.1.5 and earlier, 2.2.8 and earlier
- BlackBerry QNX OS for Medical 2.0.2 and earlier
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory