Out-of-Bounds Write Vulnerability in QNX SDP Image Codec
CVE-2025-2474

9.8CRITICAL

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
10 June 2025

What is CVE-2025-2474?

An out-of-bounds write vulnerability exists within the PCX image codec in QNX SDP, impacting versions 8.0, 7.1, and 7.0. This flaw can be exploited by unauthenticated attackers to potentially trigger a denial-of-service condition or execute arbitrary code within the context of the process utilizing the image codec. It is crucial for users of the affected versions to be aware of this vulnerability and apply necessary security measures to safeguard their systems.

Affected Version(s)

QNX Software Development Platform (SDP) 8.0, 7.1 and 7.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2474 : Out-of-Bounds Write Vulnerability in QNX SDP Image Codec