An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HBlackberry Qnx Os For Medical
OSBlackberry≤ 1.1.1Blackberry Qnx Os For Safety
OSBlackberry≤ 1.0.2Blackberry Qnx Software Development Platform
APPBlackberry6.5.0< 6.5.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDoS
Related vulnerabilities
CVE-2025-2474CRITICAL9.8PL ✓same product
Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS
CVE-2024-48856CRITICAL9.8PL ✓same product
Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS
CVE-2024-35213CRITICAL9.0PL ✓same product
Podatność improper input validation w SGI Image Codec QNX SDP
CVE-2021-32024CRITICAL9.8PL ✓same product
RCE w kodeku obrazów BMP w BlackBerry QNX SDP
CVE-2020-6932CRITICAL10.0PL ✓same product
RCE i ujawnienie informacji w serwerze slinger — BlackBerry QNX SDP