CVE-2026-4017 Details
Description
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
A buffer overflow vulnerability has been identified in the QNX Neutrino kernel, specifically within the entry handler of the TraceEvent system call. This vulnerability could allow an attacker with local access to cause information disclosure, data tampering, or a crash of the kernel. The issue affects multiple versions of the QNX Software Development Platform and QNX OS for Safety, as well as QNX OS for Medical.
Users are advised to update to QNX SDP 7.1, QNX SDP 7.0, QNX OS for Safety 2.2.9, QNX OS for Safety 2.1.6, QNX OS for Safety 2.0.4, or QNX OS for Medical 2.0.3. These updates are available through the QNX Software Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.blackberry.com/pkb/s/article/141213 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BlackBerry QNX Software Development Platform | 7.1 7.0 |
CPE
Remediation
| |
| BlackBerry QNX OS for Safety | 2.2.8 (semver) 2.1.5 (semver) 2.0.3 (semver) |
CPE
Remediation
| |
| BlackBerry QNX OS for Medical | 2.0.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion