SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-40272

HIGH · CVSS 7 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The traceparser library's decode() function is vulnerable to improper input validation, allowing attackers to exploit corrupted kernel trace event log (.kev) files. This could lead to arbitrary code execution or crashes in processes utilizing libtraceparser on QNX systems. Organizations using QNX should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-40272
Severity
HIGH
CVSS
7
EPSS
0.11%

Original NVD Description

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or targets.