CVE-2026-40272: Vulnerability in the QNX libtraceparser Impacts QNX Software Development Platform
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40272?
The severity of CVE-2026-40272 is rated high with a score of 7.
How does CVE-2026-40272 impact QNX Software Development Platform?
CVE-2026-40272 impacts the QNX Software Development Platform by allowing attackers to execute arbitrary code or crash processes due to improper input validation in the libtraceparser.
How do I fix CVE-2026-40272?
To fix CVE-2026-40272, ensure that you apply the latest patches and updates provided by QNX for the libtraceparser.
What kind of attack can exploit CVE-2026-40272?
CVE-2026-40272 can be exploited through a corrupted kernel trace event log (.kev) file presented to systems using the libtraceparser.
What is the root cause of CVE-2026-40272?
The root cause of CVE-2026-40272 is improper input validation in the decode() function of the traceparser library.