ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI disclosed an out-of-bounds write flaw (CVE-2026-40272) in BlackBerry QNX KEV file parsing enabling remote code execution.
The Zero Day Initiative published ZDI-26-566 describing an out-of-bounds write vulnerability in BlackBerry QNX KEV file parsing. Remote code execution requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned a CVSS score of 7.8 and the CVE identifier CVE-2026-40272.
- Out-of-bounds write in QNX KEV file parsing allows arbitrary code execution
- User interaction required; CVSS 7.8
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-40272 | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to ex Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets. NVD description · AI analysis pending | 7.0 | <1% | — | — |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BlackBerry QNX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40272.
This source does not provide full text. Read it at zerodayinitiative.com.