ZDI-CAN-30346: ZDI-26-566: BlackBerry QNX KEV File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BlackBerry QNX. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40272.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30346?
ZDI-CAN-30346 has a CVSS rating of 7.8, indicating it is a high-risk vulnerability.
How do I fix ZDI-CAN-30346?
To remediate ZDI-CAN-30346, ensure that you apply the latest patches or updates provided by BlackBerry for QNX.
What type of vulnerability is ZDI-CAN-30346?
ZDI-CAN-30346 is an out-of-bounds write vulnerability that allows remote code execution.
What products are affected by ZDI-CAN-30346?
ZDI-CAN-30346 affects installations of BlackBerry QNX.
Is user interaction required to exploit ZDI-CAN-30346?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file to exploit ZDI-CAN-30346.