Impact
An improper TOCTOU race condition in the TraceEvent system call’s trace commands can allow a local attacker with the PROCMGR_AID_TRACE capability to read restricted kernel data, alter memory contents, or cause a kernel crash. The flaw stems from a concurrent update of a classified as CWE‑367, and can compromise confidentiality, integrity, or availability of the QNX Neutrino system.
Affected Systems
The vulnerability affects BlackBerry’s QNX OS for Medical, QNX OS for Safety, and the QNX Software Development Platform. Specific version information is not listed. Event implementation is potentially impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is under 1 %, implying a very low likelihood of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Attack requires local access with PROCMGR_AID_TRACE, making it an intra-system threat that could be leveraged by a privileged user or during a privilege escalation.
OpenCVE Enrichment