Impact
Insufficient parameter validation in the SchedGet() system call allows a local attacker to trigger a QNX Neutrino kernel crash, leading to a system halt and loss of availability. The flaw, input validation weakness, does not provide code execution or privilege escalation beyond the local context.
Affected Systems
BlackBerry Ltd.’s QNX OS for Medical, QNX OS for Safety, and QNX Software Development Platform are affected. Version information is not disclosed, so any release that contains the vulnerable SchedGet() implementation may be impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.2, indicating moderate impact, and an EPSS score of less than 1%, implying a very low probability of exploitation at present. It is not listed in CISA’s KEV catalog. Exploitation requires local physical or privileged access; therefore, strong local‑access controls mitigate the risk while the vulnerability remains present.
OpenCVE Enrichment