Sentry kernel has incomplete ownership check for IRQ line manipulation
Published Apr 17, 2026
5.1
MEDIUMCVSS 3.1
EPSS 0.16%
Description
The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to interact with another task's IRQ line through the __sys_int_* syscall familly. Prior to version 0.4.7, this can lead to DoS and covert-channels between this task and the outer world. A patch is available in version 0.4.7. As a workaround, reduce tasks that have the DEV and IO capability to a single one.
Affected products
-
- Version < 0.4.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Camelot-OS | Sentry-Kernel | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23603 Advisory
- https://github.com/camelot-os/sentry-kernel/commit/150b7edd2c5b0da0a8baeed3135ddde613b08081 x_refsource_MISC
- https://github.com/camelot-os/sentry-kernel/pull/108 x_refsource_MISC
- https://github.com/camelot-os/sentry-kernel/security/advisories/GHSA-5hgv-rg2f-79pg x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23603 | Advisory | |
| https://github.com/camelot-os/sentry-kernel/commit/150b7edd2c5b0da0a8baeed3135ddde613b08081 | x_refsource_MISC | |
| https://github.com/camelot-os/sentry-kernel/pull/108 | x_refsource_MISC | |
| https://github.com/camelot-os/sentry-kernel/security/advisories/GHSA-5hgv-rg2f-79pg | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.