Impact
A TOCTOU race condition in the Automotive Software platform built on QNX can cause memory corruption while processing I2C transfer requests. The flaw arises from an imbalance between memory allocation and data copying, potentially enabling an attacker to corrupt critical memory areas, disrupt vehicle control functions, or execute arbitrary code. The weakness is formally mapped to CWE‑367, reflecting a race‑condition vulnerability with potential for severe integrity and availability impact.
Affected Systems
Qualcomm Snapdragon products that run the QNX‑based automotive platform are affected. Specific firmware versions are not listed in the available data, so any deployment using this platform layer should be scrutinized for the presence of the race condition.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, yet the EPSS score of less than 1% suggests that, so far, exploitability in the wild has been limited. The vulnerability is not included in the CISA KEV catalog, indicating no known large‑scale exploitation events. Because the flaw hinges on a timing discrepancy during memory operations, an attacker would need the ability to influence the I2C transfer request flow, making the attack vector likely local or specific to compromised components within the vehicle’s I2C bus. Should an exploit be executed, it could lead to uncontrolled memory corruption and potential system rollback or denial of service.
OpenCVE Enrichment