Description
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to trigger use-after-free and invalid pointer dereferences on kernel configuration objects, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests through the piControl character device.
Published: 2026-08-14
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition exists in the configuration and process‑image management functions of KUNBUS piControl. Concurrent crafted requests to the piControl character device cause a use‑after‑free and invalid pointer dereference on kernel configuration objects, leading to kernel memory corruption. The resulting exploit yields a denial‑of‑service condition for the affected system.

Affected Systems

The vulnerability affects KUNBUS piControl version 2.6.2. A local authenticated user who can issue requests to the piControl character device is required to exploit it.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. EPSS data is unavailable and the flaw is not listed in CISA KEV, but local attackers can trigger kernel corruption simply by sending concurrent requests. The attack vector is a local‑authenticated user sending crafted operations to the device, which can be performed without remote network access.

Generated by OpenCVE AI on August 14, 2026 at 16:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched version of KUNBUS piControl as soon as it becomes available
  • Restrict access to the piControl character device by limiting its ownership and permissions to trusted system users
  • Disable or uninstall the piControl kernel module if it is not needed in the environment

Generated by OpenCVE AI on August 14, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to trigger use-after-free and invalid pointer dereferences on kernel configuration objects, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests through the piControl character device.
Title Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl
Weaknesses CWE-362
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-08-14T15:01:39.483Z

Reserved: 2026-06-24T13:50:25.222Z

Link: CVE-2026-13197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:49.523

Modified: 2026-08-14T16:16:49.523

Link: CVE-2026-13197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T16:30:05Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')