CVE-2024-35215

MEDIUM

QNX Software Development Platform 7.0-7.1 - Denial of Service via IP Socket Options Processing

Title source: llm
STIX 2.1

Description

NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.

References (1)

Core 1
Core References

Scores

CVSS v3 6.2
EPSS 0.0016
EPSS Percentile 5.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (1)
blackberry/qnx_software_development_platform 7.0 - 8.0
Published Oct 08, 2024
Tracked Since Feb 18, 2026