Home
Developer Resources
Technical Articles

QNX Technical Articles

Sensor Framework and Multimedia GA Update for CVEs: Release Notes

Date of this edition: June 23, 2021

Target OS: This update is compatible with targets that are running QNX® Neutrino® 7.1.

Host OS: To install this update, you must have installed the QNX Software Development Platform (SDP) 7.1 and the Sensor Framework for QNX SDP 7.1 on one of the following development hosts:

  • Microsoft Windows 10 Pro 64-bit or Windows 8.1 Pro 64-bit
  • macOS version 10.14 or 10.15
  • Linux Red Hat Enterprise Linux 7 64-bit or Ubuntu Desktop 18.04 LTS 64-bit, on x86_64 processors (QNX SDP isn't supported on Linux on ARM processors)

Contents

Throughout this document, you may see reference numbers associated with particular issues, changes, etc. When corresponding with our Technical Support staff about a given issue, please quote the relevant reference number. You might also find the reference numbers useful for tracking issues as they become fixed.

What's in this update?

This update provides newer versions of the OSR OpenCV, Pixman, and Cairo libraries that fix security vulnerabilities, and newer versions of Sensor Framework applications and libraries that use these OSR libraries. The security issues fixed are those found in the version of the OSR libraries shipped with the Sensor Framework for QNX SDP 7.1 release.

To install this update, you must install the following packages found under the Updates or Available tab:

  • Under QNX Software Development Platform -> Sensor Framework:

    Name Package Description Build ID
    QNX SDP 7.1 Sensor Framework Sensor Support (with Debug Symbols) com.qnx.qnx710.target.sf.sensor Sensor and ADAS libraries and example applications that support non-camera sensors 270
    QNX SDP 7.1 Sensor Framework ADAS Library Algorithm Plugin Examples (with Debug Symbols) com.qnx.qnx710.target.sf.libadas.plugins ADAS library algorithm plugins that support traffic light detection 270
    QNX SDP 7.1 Sensor Framework ADAS Library OpenCV Examples (with Debug Symbols) com.qnx.qnx710.target.sf.opencv_examples ADAS library algorithm plugins that use OpenCV 270
  • Under QNX Software Development Platform -> Source Bundles:

    Name Package Description Build ID
    QNX SDP 7.1 Sensor Framework OpenCV Examples Source Code com.qnx.qnx710.target.sf.opencv_examples.source Source code for the ADAS plugins that use OpenCV 270
  • Under Prebuilt Open Source Packages -> OSR:

    Name Package Description Build ID
    QNX SDP 7.1 OpenCV (with Debug Symbols) com.qnx.qnx710.osr.opencv Open Source Computer Vision Library 13
    QNX SDP 7.1 Pixman (with Debug Symbols) com.qnx.qnx710.osr.pixman Low-level library for pixel manipulation 47
    QNX SDP 7.1 Cairo (with Debug Symbols) com.qnx.qnx710.osr.cairo 2D graphics library with support for EGL/GLES output target 47

To see a list of the contents of a package, right-click it in the QNX Software Center, choose Properties, and then click Package Contents.

Fixed issues

This update fixes the known security vulnerabilities present in the following versions of OSR libraries:

  • OpenCV v3.2.0 in Sensor Framework for QNX SDP 7.1 (17 high severity, 2 medium) (Ref# J2898437)
  • Cairo v1.16.0 in Sensor Framework for QNX SDP 7.1 (3 Medium, 1 high) (Ref# J2898435)

Known issues

  • This update will fail to install if you've installed both the Sensor Framework OSR Cairo Update and the Multimedia for QNX SDP 7.1 Update. You will see an error message about a conflicting dependency related to the Cairo library. (Ref# J2902980)

    Workaround:

    • If you're running QNX Software Center 1.7 or later, click the Remediate button found below the package list area in the Install dialog.
    • If you're running QNX Software Center 1.6.2 or earlier, go to the Available tab and install the QNX SDP 7.1 Cairo (with Debug Symbols) package before installing the rest of the packages in this update.

Technical support

For information about technical support for any QNX product, go to the Developers menu on our website (www.qnx.com). You'll find a wide range of support options, including community forums.