WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Joint WaterISAC – U.S. Environmental Protection Agency Advisory: BadAlloc Vulnerability Impacting BlackBerry QNX RTOS
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint WaterISAC – U.S. Environmental Protection Agency Advisory: BadAlloc Vulnerability Impacting BlackBerry QNX RTOS

Author: Jennifer Walker

Created: Tuesday, August 17, 2021 - 18:19

Categories: Cybersecurity, OT-ICS Security, Security Preparedness

Joint WaterISAC – U.S. Environmental Protection Agency Advisory

On Tuesday, August 17, 2021 the Cybersecurity and Infrastructure Security Agency (CISA) published an alert highlighting a vulnerability named “BadAlloc” (CVE-2021-22156) that has been identified in the BlackBerry (BB) QNX Real Time Operating System (RTOS) that is used in a wide range of Industrial Control Systems (ICS). Additionally, several other manufacturers have developed their own proprietary versions of this RTOS using similar technology to the BB QNX, which leaves their products vulnerable to the BadAlloc flaw as well.

Attention: Every water and wastewater utility should determine the presence of impacted RTOS devices within their environments. Asset owners are encouraged to check this original CISA ICS Advisory (ICSA-21-119-04) Multiple RTOS (Update C) for a partial list of impacted products. In addition, asset owners should work with IT and OT support staff, system integrators, and ICS and IoT manufacturers to determine if any process control systems are vulnerable to this flaw and consider patching or applying appropriate compensating controls/workarounds immediately until a patch can be applied.

What you need to know.

  • A high-risk vulnerability impacting real-time operating systems (RTOS’s) known as BadAlloc has been identified in BlackBerry QNX RTOS Versions 6.5 SP1 and earlier.
  • BadAlloc was originally disclosed by Microsoft in April 2021 as a type of remote code execution vulnerability affecting Internet of Things (IoT) devices and industrial equipment that is specifically used in industrial/OT, medical, and corporate networks.
  • In May 2021, CISA issued a public disclosure regarding BadAlloc and its impact to RTOS’s in other manufacturer’s products.
  • BlackBerry states that QNX RTOS is used in more than 500 million endpoint products, including more than 300 million embedded systems around the world across a range of industries such as aerospace, defense, automotive, commercial vehicles, heavy machinery, industrial controls, medical, rail, and robotics. Visit BlackBerry for a list of affected products.
  • Given widespread usage among industrial control systems, it is important for water and wastewater sector entities to assess their environments for deployment of vulnerable components.

For more on why this is a concern, patch status, recommended actions, and additional infomation, access the attachment below.

WaterISAC and EPA will continue to share information with members and partners as more is learned about this vulnerability. Likewise, all water and wastewater utilities are encouraged to share information with WaterISAC by emailing an*****@*******ac.org, calling 866-H20-ISAC, or using the online incident reporting form.

Attached Files:

WaterISAC-EPA Joint Advisory_BlackBerry QNX_BadAlloc_FINAL

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 7, 2026)

May 7, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) Gate 15 TARGET Report – Identity Centric Attacks: The Shift from Network to Identity as the Primary Attack Surface

May 7, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) CISA and Partners Release Guidance for Careful Adoption of Agentic AI Services

May 7, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar