High severity7.0NVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
CVE-2026-40272
CVE-2026-40272
Description
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityZero Day Initiative · Aug 13, 2026