CVE-2021-22156
Published: Aug 17, 2021
Modified: Aug 22, 2025
CVSS v3.1
9.0
Description
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.
| Vendor | Product | Versions |
|---|---|---|
BlackBerry | QNX Software Development Platform (SDP), QNX OS for Medical and QNX OS for Safety | affected QNX SDP 6.5.0 SP1 and earlieraffected QNX OS for Medical 1.1 and earlieraffected QNX OS for Safety 1.0.1 and earlier |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now