CVE-2026-0515CWE-233
Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
Medium · published July 14, 2026
What it is
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
The record
Technical detail
- CVSS v3.1
- 6.2 · MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00149 · 4.4th percentile
- Weakness
- CWE-233 · Improper Handling of Parameters
- Published
- 2026-07-14T17:13Z
EPSS history
Timeline