CVE-2026-40337

medium

Description

The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to interact with another task's IRQ line through the __sys_int_* syscall familly. Prior to version 0.4.7, this can lead to DoS and covert-channels between this task and the outer world. A patch is available in version 0.4.7. As a workaround, reduce tasks that have the DEV and IO capability to a single one.

References

https://github.com/camelot-os/sentry-kernel/security/advisories/GHSA-5hgv-rg2f-79pg

https://github.com/camelot-os/sentry-kernel/pull/108

https://github.com/camelot-os/sentry-kernel/commit/150b7edd2c5b0da0a8baeed3135ddde613b08081

Details

Source: Mitre, NVD

Published: 2026-04-18

Updated: 2026-04-18

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:L/AC:L/Au:M/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.1

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H

Severity: Medium