Description
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
Published: 2026-07-14
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient parameter validation in the SchedGet() system call allows a local attacker to trigger a QNX Neutrino kernel crash, leading to a system halt and loss of availability. The flaw, input validation weakness, does not provide code execution or privilege escalation beyond the local context.

Affected Systems

BlackBerry Ltd.’s QNX OS for Medical, QNX OS for Safety, and QNX Software Development Platform are affected. Version information is not disclosed, so any release that contains the vulnerable SchedGet() implementation may be impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 6.2, indicating moderate impact, and an EPSS score of less than 1%, implying a very low probability of exploitation at present. It is not listed in CISA’s KEV catalog. Exploitation requires local physical or privileged access; therefore, strong local‑access controls mitigate the risk while the vulnerability remains present.

Generated by OpenCVE AI on July 31, 2026 at 06:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch that addresses the SchedGet() parameter validation flaw in QNX Neutrino.
  • If an update is unavailable, restrict local execution of the SchedGet() syscall by adjusting system configuration or firewall rules to block its use.
  • Upgrade to a QNX OS or QNX Software Development Platform release that includes the fix once it becomes available.
  • Enforce strict local‑user privilege controls.

Generated by OpenCVE AI on July 31, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Blackberry
Blackberry qnx Os For Medical
Blackberry qnx Os For Safety
Blackberry qnx Software Development Platform
Vendors & Products Blackberry
Blackberry qnx Os For Medical
Blackberry qnx Os For Safety
Blackberry qnx Software Development Platform

Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
Title Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
Weaknesses CWE-233
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Blackberry Qnx Os For Medical Qnx Os For Safety Qnx Software Development Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: blackberry

Published:

Updated: 2026-07-14T23:35:27.900Z

Reserved: 2025-12-10T15:04:59.507Z

Link: CVE-2026-0515

cve-icon Vulnrichment

Updated: 2026-07-14T23:35:24.493Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:00:16Z

Weaknesses
  • CWE-233

    Improper Handling of Parameters