Impact
Buffer overflow in the entry handler of the TraceEvent() system call in QNX Neutrino allows an attacker with local access to overflow a buffer, potentially leading to information disclosure, data tampering, or a kernel crash. The flaw is a classic stack‑based buffer overflow (CWE‑121). Because the overflow occurs inside a privileged system call, a successful exploitation could alter kernel memory, compromise integrity, or trigger an unplanned reboot, impacting the stability and confidentiality of the operating environment.
Affected Systems
Affected vendors include BlackBerry Ltd., whose QNX OS for Medical, QNX OS for Safety, and QNX Software Development Platform contain the vulnerable kernel. The advisory does not list specific affected versions; therefore any releases prior to the published fix that still contain the unpatched TraceEvent system call are potentially vulnerable. Organizations using any of these products should evaluate the package version and consider the risk of local exploitation.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, while the EPSS score of less than 1% suggests a modest likelihood of exploitation at present. The vulnerability is not in CISA’s KEV catalog. Local access is required, so the threat is limited to users with physical or local network privileges. An attacker would need to invoke the TraceEvent system call with crafted parameters to trigger the overflow, which implies a relatively high skill threshold and limited attack surface compared to remote exploits.
OpenCVE Enrichment