CVE-2026-40272

Summary

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.

Affected Software

VendorProductVersion RangeStatus
BlackBerry LtdQNX Software Development Platform8.0affected
BlackBerry LtdQNX Software Development Platformcpe:2.3:a:blackberry:qnx_software_development_platform:8.0:*:*:*:*:*:*:*affected
BlackBerry LtdQNX Software Development Platform7.1affected
BlackBerry LtdQNX Software Development Platformcpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:*affected
BlackBerry LtdQNX Software Development Platform7.0affected
BlackBerry LtdQNX Software Development Platformcpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:*affected

Weaknesses

  • CWE-1284: CWE-1284 Improper validation of specified quantity in input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References