Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40337

20
FAUCET Score

CVE-2026-40337 is a capability escalation vulnerability in the Sentry kernel, a security-focused micro-kernel for embedded systems. Prior to version 0.4.7, tasks granted DEV or IO capabilities can improperly interact with other tasks' IRQ lines through the __sys_int_* syscall family, creating security boundaries violations. The vulnerability carries a CVSS score of 5.1 (Medium) with local attack vector and high privileges required, resulting in potential denial of service and the establishment of covert channels between isolated tasks. The attack has low complexity and can impact system availability while potentially enabling information disclosure. There is no current evidence of active exploitation in the wild. The vulnerability has not been added to the Known Exploited Vulnerabilities catalog, maintains an inactive status on vulnerability hotlists, and shows minimal community attention relative to other CVEs. Patched versions (0.4.7 and later) are available, and administrators can immediately implement the workaround of consolidating DEV and IO capabilities to a single task until patching is completed.

Impacted Technologies

VendorProductVersion(s)CPE
Camelot-OsSentry-Kernel
< 0.4.7CNA affected

CVSS Data

CVSS version used by this source: 3.1

5.1MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
0.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
5.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 37th percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / camelot-os/sentry-kernel/commit/150b7edd2c5b0da0a8baeed3135ddde613b08081
github.com / camelot-os/sentry-kernel/pull/108
github.com / camelot-os/sentry-kernel/security/advisories/GHSA-5hgv-rg2f-79pg