Skip to content
BlackBerryCVE-2026-4018

BlackBerry QNX: race condition

Medium6.4CVE-2026-4018 · Published Jul 14, 2026 · updated Jul 15, 2026

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.

BlackBerry advisory

Affected versions

PackageAffectedFixed in
QNX OS for Medical
Product
<= 2.0.2 and earlierNo fix yet
<= cpe:2.3:o:blackberry:qnx_os_for_medical:2.0:2:*:*:*:*:*:*No fix yet
QNX OS for Safety
Product
<= 2.2.8 and earlierNo fix yet
<= cpe:2.3:o:blackberry:qnx_os_for_safety:2.2:8:*:*:*:*:*:*No fix yet
<= 2.1.5 and earlierNo fix yet
<= cpe:2.3:o:blackberry:qnx_os_for_safety:2.1:5:*:*:*:*:*:*No fix yet
QNX Software Development Platform
Product
<= 7.1No fix yet
<= cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*No fix yet
<= 7.0No fix yet
<= cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-367

More BlackBerry advisories

All BlackBerry
Advisory
BlackBerry AtHoc IWS: cross-site scripting
Medium5.3Aug 11
BlackBerry QNX Software Development Platform: improper input validation
High7.0Jul 29
BlackBerry UEM: improper input validation
Medium5.9Jul 28
BlackBerry UEM: cross-site scripting
High8.6Jul 28
BlackBerry QNX: buffer overflow
High7.4Jul 14
BlackBerry QNX: attacker could cause a crash of the QNX Neutrino kernel
Medium6.2Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.