Executive brief
A vulnerability exists in the QNX Neutrino kernel, a real-time operating system used in automotive, medical, and industrial systems. An attacker with local access and specific administrative privileges could exploit a timing flaw to crash the system, view sensitive information, or tamper with data. This could lead to service outages or unauthorized modifications in safety-critical environments.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition exists within specific trace commands of the TraceEvent() system call in the QNX Neutrino kernel. To exploit this, an attacker must have local access and possess the PROCMGR_AID_TRACE ability. The vulnerability arises from improper synchronization when handling trace events, allowing a window where data can be modified between its validation and its use. Successful exploitation can result in information disclosure, data tampering, or a kernel-level denial of service (crash). The issue affects QNX Software Development Platform (SDP) versions 7.0 and 7.1, as well as specific versions of QNX OS for Safety and Medical.
Affected products
- BlackBerry QNX Software Development Platform 7.0, 7.1
- BlackBerry QNX OS for Safety 2.0.3 and earlier, 2.1.5 and earlier, 2.2.8 and earlier
- BlackBerry Ltd. QNX OS for Medical 2.0.2 and earlier
Timeline
- 2026-07-14: advisory: Advisory published by BlackBerry and NVD