CVE-2026-40337 is a capability escalation vulnerability in the Sentry kernel, a security-focused micro-kernel for embedded systems. Prior to version 0.4.7, tasks granted DEV or IO capabilities can improperly interact with other tasks' IRQ lines through the __sys_int_* syscall family, creating security boundaries violations. The vulnerability carries a CVSS score of 5.1 (Medium) with local attack vector and high privileges required, resulting in potential denial of service and the establishment of covert channels between isolated tasks. The attack has low complexity and can impact system availability while potentially enabling information disclosure. There is no current evidence of active exploitation in the wild. The vulnerability has not been added to the Known Exploited Vulnerabilities catalog, maintains an inactive status on vulnerability hotlists, and shows minimal community attention relative to other CVEs. Patched versions (0.4.7 and later) are available, and administrators can immediately implement the workaround of consolidating DEV and IO capabilities to a single task until patching is completed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Camelot-Os | Sentry-Kernel | < 0.4.7CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.