What is CVE-2026-40272?
CVE-2026-40272 is an improper input validation vulnerability in the decode() function of the traceparser library used in QNX systems. It could allow an attacker to execute arbitrary code or crash processes via a corrupted .kev trace event file. Affected QNX hosts or targets should be patched immediately.
Azərbaycanca: CVE-2026-40272, QNX sistemlərində istifadə olunan traceparser kitabxanasının decode() funksiyasında düzgün olmayan giriş yoxlaması zəifliyidir. Bu, zədələnmiş .kev trace faylı vasitəsilə hücumçuya öz kodunu icra etməyə və ya prosesi çökdürməyə imkan verə bilər. QNX hostlarına təsir edir, dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ1
What file type must an attacker target to exploit CVE-2026-40272?
An attacker can exploit this vulnerability via a corrupted .kev trace event file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.