Executive brief
A vulnerability has been identified in the QNX Neutrino kernel, a real-time operating system used in critical automotive, medical, and industrial systems. An attacker with local access to a device could exploit this flaw to crash the system, tamper with sensitive data, or access restricted information. This could lead to service disruptions or unauthorized control over safety-critical equipment.
Technical details
A stack-based buffer overflow (CWE-121) exists in the entry handler of the TraceEvent() system call within the QNX Neutrino kernel. The vulnerability is triggered when the kernel improperly handles input during system call processing. An attacker with local access can exploit this to overwrite kernel memory, potentially leading to arbitrary code execution in kernel mode, data corruption, or a Denial of Service (kernel panic). While the attack requires local access, the CVSS assessment indicates high complexity (AC:H) but no specific privileges are required (PR:N). Affected products include QNX Software Development Platform (SDP) 7.0/7.1 and specialized QNX OS variants for Safety and Medical applications.
Affected products
- BlackBerry Ltd QNX Software Development Platform 7.0, 7.1
- BlackBerry Ltd QNX OS for Safety 2.0.3 and earlier, 2.1.5 and earlier, 2.2.8 and earlier
- BlackBerry Ltd. QNX OS for Medical 2.0.2 and earlier
Timeline
- 2026-07-14: advisory: Initial advisory published by BlackBerry and NVD