Home

Description

Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.

PUBLISHED Reserved 2025-07-23 | Published 2026-01-13 | Updated 2026-01-13 | Assigner blackberry




MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-476 NULL Pointer Dereference

Product status

Default status
unaffected

7.1 and 7.0 (custom)
affected

cpe:2.3:a:blackberry:qnx_software_development_platform:7.1:*:*:*:*:*:*:* (cpe)
affected

cpe:2.3:a:blackberry:qnx_software_development_platform:7.0:*:*:*:*:*:*:* (cpe)
affected

Default status
unaffected

2.2.7 and earlier (custom)
affected

cpe:2.3:o:blackberry:qnx_os_for_safety:2.2:7:*:*:*:*:*:* (cpe)
affected

2.1.4 and earlier (custom)
affected

cpe:2.3:o:blackberry:qnx_os_for_safety:2.1:4:*:*:*:*:*:* (cpe)
affected

2.0.2 and earlier (custom)
affected

cpe:2.3:o:blackberry:qnx_os_for_safety:2.0:2:*:*:*:*:*:* (cpe)
affected

Default status
unaffected

2.0.1 and earlier (custom)
affected

cpe:2.3:o:blackberry:qnx_os_for_medical:2.0:1:*:*:*:*:*:* (cpe)
affected

References

support.blackberry.com/pkb/s/article/141027 vendor-advisory

cve.org (CVE-2025-8090)

nvd.nist.gov (CVE-2025-8090)

Download JSON