Dismissed
(no matching packages found)
Permalink
CVE-2026-40272
7.0 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created & dismissed (no matching packages found) suggestion
Vulnerability in the QNX libtraceparser Impacts QNX Software Development Platform
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.
References
-
https://support.blackberry.com/pkb/s/article/141229 vendor-advisory
Affected products
QNX Software Development Platform
- ==cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:*
- ==7.0
- ==8.0
- ==cpe:2.3:a:blackberry:qnx_software_development_platform:8.0:*:*:*:*:*:*:*
- ==7.1
- ==cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*