CVE-2026-0515CWE-233

Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety

Medium · published July 14, 2026

CVSS v3.1
6.2
EPSS
0%
Percentile
4.4
In the wild
Unconfirmed
What it is

Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.

The record
Technical detail
CVSS v3.1
6.2 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00149 · 4.4th percentile
Weakness
CWE-233 · Improper Handling of Parameters
Published
2026-07-14T17:13Z
EPSS history
Timeline
  • 14 JUL 17:13Z
    Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
    cvelistv5