CVE-2026-4017: Buffer overflow in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
Published Jul 14, 2026
·Updated
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
Affected Software
3 affected components
QNX QNX Neutrino kernel
QNX QNX Software Development Platform
QNX QNX OS for Safety
Event History
Jul 14, 2026
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-4017?
CVE-2026-4017 has a severity rating of high with a score of 7.4.
2
How do I fix CVE-2026-4017?
To fix CVE-2026-4017, upgrade to the latest version of the QNX Neutrino kernel or apply any available patches provided by the vendor.
3
What software is affected by CVE-2026-4017?
CVE-2026-4017 affects the QNX Neutrino kernel and versions of the QNX Software Development Platform and QNX OS for Safety.
4
What are the potential consequences of exploiting CVE-2026-4017?
Exploiting CVE-2026-4017 could lead to information disclosure, data tampering, or a crash of the QNX Neutrino kernel.
5
Is local access required to exploit CVE-2026-4017?
Yes, exploiting CVE-2026-4017 requires local access to the system.