← Vulnerability feed

Vulnerability record · CVE-2021-22156 · published 17 August 2021

CVE-2021-22156: Blackberry qnx software development platform integer overflow vulnerability

Blackberry · Qnx Software Development Platform

An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

9.8 CVSS 3.1 Critical EPSS 1.8% · top 22.5% CWE-190 · Integer overflow
9.8CVSS 3.1 base score, v2 6.8
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-2474Blackberry qnx software development platform out-of-bounds write vulnerabilityOut-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …EPSS 0.73%9.8CVE-2024-48856Blackberry qnx software development platform out-of-bounds write vulnerabilityOut-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …EPSS 0.62%9.8CVE-2021-32024Blackberry qnx software development platform vulnerabilityA remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execu…EPSS 1.8%9.8CVE-2020-6932Blackberry qnx software development platform vulnerabilityAn information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versi…EPSS 3.6%9.6CVE-2017-3891Blackberry qnx software development platform incorrect authorization vulnerabilityIn BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with…EPSS 1.3%9.0CVE-2024-35213Blackberry qnx software development platform vulnerabilityAn improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially caus…EPSS 0.52%7.8CVE-2021-32025Blackberry qnx momentics vulnerabilityAn elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0,…EPSS 0.18%7.8CVE-2019-8998Blackberry qnx software development platform vulnerabilityAn information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBer…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2021-22156), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.