Junglewise Threat Intelligence

CVE-2026-40272: BlackBerry QNX traceparser improper input validation in decode function

CVE-2026-40272 · Severity: high · CVSS 7 · Published 2026-07-29

Technologies: Blackberry QNX Software Development Platform. Vendors: Blackberry.

Executive brief

A vulnerability exists in the BlackBerry QNX traceparser library, which is used to analyze system performance and kernel events. An attacker could provide a specially crafted or corrupted event log file that, when opened by a user, could cause the system to crash or allow the execution of unauthorized code. This could lead to a loss of system availability or the compromise of sensitive operational data on QNX-based hosts.

Technical details

An improper input validation vulnerability (CWE-1284) exists in the decode() function within libtraceparser. The flaw is triggered when the library processes a corrupted kernel trace event log (.kev) file. While the attack vector is local, it requires a high degree of complexity and user interaction, as a user must be enticed to open the malicious file. Successful exploitation can lead to arbitrary code execution or a denial-of-service (crash) in any process utilizing the affected library on QNX hosts or targets. The vulnerability affects QNX Software Development Platform versions 7.0, 7.1, and 8.0.

Affected products

  • BlackBerry QNX Software Development Platform 7.0, 7.1, 8.0

Timeline

  • 2026-07-29: advisory: Initial advisory published by BlackBerry and NVD.

References

Related threats