CVE-2026-40272
BlackBerry Ltd QNX Software Development Platform
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.
- CVSS
- 7
- EPSS
- 0.11% 1.63% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.30