Skip to content
BlackBerryCVE-2026-40272

BlackBerry QNX Software Development Platform: improper input validation

High7.0CVE-2026-40272 · Published Jul 29, 2026 · updated Jul 30, 2026

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.

BlackBerry advisory

Affected versions

PackageAffectedFixed in
QNX Software Development Platform
Product
<= 8.0No fix yet
<= cpe:2.3:a:blackberry:qnx_software_development_platform:8.0:*No fix yet
<= 7.1No fix yet
<= cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1284

More BlackBerry advisories

All BlackBerry
Advisory
BlackBerry AtHoc IWS: cross-site scripting
Medium5.3Aug 11
BlackBerry UEM: improper input validation
Medium5.9Jul 28
BlackBerry UEM: cross-site scripting
High8.6Jul 28
BlackBerry QNX: buffer overflow
High7.4Jul 14
BlackBerry QNX: race condition
Medium6.4Jul 14
BlackBerry QNX: attacker could cause a crash of the QNX Neutrino kernel
Medium6.2Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.