7.4

CVE-2026-4017

Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety

Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerBlackBerry Ltd
≫
Produkt QNX Software Development Platform
Default Statusunaffected
Version 7.1
Status affected
Version cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:*
Status affected
Version 7.0
Status affected
Version cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*
Status affected
HerstellerBlackBerry Ltd
≫
Produkt QNX OS for Safety
Default Statusunaffected
Version 2.2.8 and earlier
Status affected
Version cpe:2.3:o:blackberry:qnx_os_for_safety:2.2:8:*:*:*:*:*:*
Status affected
Version 2.1.5 and earlier
Status affected
Version cpe:2.3:o:blackberry:qnx_os_for_safety:2.1:5:*:*:*:*:*:*
Status affected
Version 2.0.3 and earlier
Status affected
Version cpe:2.3:o:blackberry:qnx_os_for_safety:2.0:3:*:*:*:*:*:*
Status affected
HerstellerBlackBerry Ltd.
≫
Produkt QNX OS for Medical
Default Statusunaffected
Version 2.0.2 and earlier
Status affected
Version cpe:2.3:o:blackberry:qnx_os_for_medical:2.0:2:*:*:*:*:*:*
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Blackberry 7.4 1.4 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).