Impact
A race condition exists in the configuration and process‑image management functions of KUNBUS piControl. Concurrent crafted requests to the piControl character device cause a use‑after‑free and invalid pointer dereference on kernel configuration objects, leading to kernel memory corruption. The resulting exploit yields a denial‑of‑service condition for the affected system.
Affected Systems
The vulnerability affects KUNBUS piControl version 2.6.2. A local authenticated user who can issue requests to the piControl character device is required to exploit it.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. EPSS data is unavailable and the flaw is not listed in CISA KEV, but local attackers can trigger kernel corruption simply by sending concurrent requests. The attack vector is a local‑authenticated user sending crafted operations to the device, which can be performed without remote network access.
OpenCVE Enrichment