CyberRota Analysis
AI-GeneratedA TOCTOU race condition vulnerability in the TraceEvent() system call of the QNX Neutrino kernel can be exploited by local attackers with the PROCMGR_AID_TRACE capability, potentially leading to information disclosure, data tampering, or system crashes. Organizations using QNX Neutrino should prioritize patching this vulnerability to mitigate risks associated with local privilege escalation and system integrity.
CVE
CVE-2026-4018
Severity
MEDIUM
CVSS
6.4
EPSS
0.09%
Original NVD Description
TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.