CVE-2026-4018: TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGRAIDTRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4018?
CVE-2026-4018 has a severity rating of medium with a score of 6.4.
How do I fix CVE-2026-4018?
To remediate CVE-2026-4018, ensure that all relevant QNX Software Development Platform and QNX OS for Safety versions are updated to the patched versions provided by the vendor.
What types of attacks are possible due to CVE-2026-4018?
CVE-2026-4018 could allow attackers to cause information disclosure, data tampering, or a crash of the QNX Neutrino kernel.
Which versions of QNX are affected by CVE-2026-4018?
CVE-2026-4018 impacts specific versions of the QNX Neutrino kernel, the QNX Software Development Platform, and the QNX OS for Safety.
What type of vulnerability is CVE-2026-4018 classified as?
CVE-2026-4018 is classified as a race condition vulnerability, specifically a TOCTOU (Time of Check to Time of Use) issue.