
How can open source software meet the rigorous requirements of safety-critical systems? What role can AI, memory-safe technologies, traceability frameworks, and real-time security play in building systems that are both open and dependable?
These questions will be discussed at Open Source Summit Korea 2026, taking place on August 11–12. The event brings together developers, maintainers, technologists, community leaders, and open source professionals from across the ecosystem to share knowledge, collaborate on solutions, and discuss emerging technologies.
With sessions covering cloud infrastructure, Linux, AI and machine learning, embedded systems, security, governance, legal topics, and community strategy, Open Source Summit provides a cross-domain space where technical and non-technical contributors can connect and learn from one another.
The ELISA Project will also be part of the Safety-Critical Software track. This track focuses on the intersection of open source software and safety standards, including regulatory compliance, security updates, requirements traceability, quality assessments, safety analysis methodologies, and the technical development of safety-critical systems.
Don’t forget to add these sessions to your schedule!
As Generative AI and Agentic AI continue to evolve, cyberattacks have become increasingly automated. With hundreds of new CVEs disclosed every day and AI-powered attacks automated in zero-hour, traditional security and patch management approaches have reached their limits.
This session explores how organizations can build a lightweight hardened infrastructure and a trusted Zero-CVE environment with Red Hat AI on a proven platform that leverages the strengths of the open source ecosystem. It also examines the need for autonomous defense systems and approaches to implementing them, enabling real-time threat response while maintaining infrastructure stability through controlled AI-driven automation.
Institutional blockchain systems need collective defense, yet the data behind the vulnerabilities they discover cannot leave the institution. The OpenReagent project was launched to break that paradox through an open standard built on sharing signatures, not source. A year in, the concept has become a working technical foundation, with early benchmark evidence and first conversations with institutions testing real fit. This session shares what that foundation now enables, and what it doesn’t yet, and issues a direct call to researchers ready to deepen the technical frontier, and to institutions ready to join the initiative as early partners.
The automotive transition to Software-Defined Vehicles (SDVs) relies on mixed-criticality architectures, consolidating open-source infotainment (Automotive Grade Linux) alongside safety-critical Real-Time Operating Systems (RTOS). This virtualization boundary—often KVM/Xen—is assumed to be a secure airgap. However, guest-to-host communication requires hardware abstraction, primarily via the VirtIO standard.
This 40-minute session conducts a hardcore technical teardown of the virtqueue shared-memory mechanism, exposing how legacy C-based VirtIO backends (vhost-net) introduce critical vulnerabilities into the automotive supply chain.
The speakers will dissect a hypervisor escape utilizing custom fuzzing. By crafting malformed descriptor chains to bypass frontend validation, a compromised guest can force the host’s backend into out-of-bounds memory corruption, effectively bridging the airgap into the control plane.
Finally, the speakers will architect the open-source defense: migrating to memory-safe rust-vmm virtualization components to mathematically eliminate buffer overflows, and deploying zero-overhead eBPF probes for kernel-level I/O anomaly detection.
Popular open source operating systems like the Linux Kernel and Zephyr RTOS accept up to 9 commits per hour. Safety standards, like 61508, 26262, and others were developed without this rate of change in mind. Safety standards also expect the requirements to be explicit, which is not part of OS development processes. By using AI tools, we’re able to accelerate the analysis of OS code to derive the requirements and traceability to tests. By storing this info in tools that can import and export System Package Data eXchange (SPDX) 3.0+, we’re able to capture the requirements in a way that can be leveraged for wider system analysis necessary for safety. Associating integrity methods with the requirements and code snippets, also enables monitoring. Combining requirements traceability with precise build SBOM metadata, gives us a framework to keep a component compliant to a safety profile after a security fix.
This talk will provide a view on the latest experiments occurring with the Linux Kernel in the ELISA project, as well as in the Zephyr Safety Working group, and SPDX Functional Safety working group to extend SPDX to meet the needs of establishing these frameworks.
Join the Conversation
As open source software becomes increasingly important in automotive, industrial, medical, and other safety-critical environments, collaboration across projects, companies, standards organizations, and technical communities is essential.
The Safety-Critical Software track offers an opportunity to learn how the open source community is addressing security, compliance, traceability, virtualization, AI-assisted analysis, and long-term software maintenance. Join the ELISA Project and the wider open source community at Open Source Summit Korea 2026 to learn about the technologies, practices, and partnerships helping move safety-critical open source development forward.
Learn more about the event and register here.