CVE-2026-40272
Awaiting Analysis Awaiting Analysis - Queue

Improper Input Validation in QNX traceparser Library

Vulnerability report for CVE-2026-40272, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: BlackBerry

Description

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
blackberry libtraceparser *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation flaw in the decode() function of the traceparser library. It affects processes using libtraceparser on QNX hosts or targets. An attacker could exploit a corrupted kernel trace event log file (.kev) to execute arbitrary code or crash the affected process.

Detection Guidance

Detecting this vulnerability requires checking for corrupted kernel trace event log (.kev) files processed by libtraceparser. Inspect files with .kev extension in QNX systems and validate their integrity. No specific commands are provided in the context.

Impact Analysis

If you use QNX systems with libtraceparser, an attacker could exploit this to run malicious code on your system or cause it to crash. This could lead to data loss, unauthorized access, or denial of service on QNX hosts or targets.

Compliance Impact

This vulnerability could lead to arbitrary code execution or crashes in systems processing kernel trace event logs, potentially compromising data integrity and availability. For GDPR, this may affect confidentiality and integrity of personal data. For HIPAA, it could impact the security of protected health information if exploited.

Mitigation Strategies

Immediately update libtraceparser to the latest patched version. Avoid processing untrusted .kev files. Restrict access to kernel trace event logs to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40272. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart