Description
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to corrupt kernel heap and event-list state and disclose a small amount of adjacent kernel memory, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests from multiple threads through the piControl character device.
Published: 2026-08-14
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

KUNBUS piControl contains a race condition in its event notification subsystem that allows a local authenticated user to trigger concurrent crafted requests through the piControl character device. The improper synchronization between threads can corrupt the kernel heap and the event-list state, leading to disclosure of a small portion of adjacent kernel memory, overall kernel memory corruption, and a denial of service in the form of a system crash or reboot.

Affected Systems

The vulnerability exists in KUNBUS piControl version 2.6.2. No other affected versions or components are listed in the available data.

Risk and Exploitability

The CVSS score of 5.9 places the vulnerability in the medium severity range, and exploitation requires a local authenticated attacker who can issue concurrent requests. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Given these constraints, the likelihood of widespread exploitation is moderate; an attacker would need sufficient local privileges and the ability to generate parallel requests against the piControl device to trigger the fault.

Generated by OpenCVE AI on August 14, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch or upgrade to a fixed version of KUNBUS piControl if available.
  • Restrict access to the piControl character device so that only trusted system processes or accounts can open it, thereby limiting the ability of local users to perform concurrent crafted requests.
  • Monitor the kernel for signs of memory corruption, such as unexpected panics or crashes, and employ kernel hardening options like canaries and address-space layout randomization to reduce the impact of any remaining race.

Generated by OpenCVE AI on August 14, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to corrupt kernel heap and event-list state and disclose a small amount of adjacent kernel memory, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests from multiple threads through the piControl character device.
Title Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl
Weaknesses CWE-362
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-08-14T15:02:42.331Z

Reserved: 2026-06-24T13:50:32.381Z

Link: CVE-2026-13198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:49.713

Modified: 2026-08-14T16:16:49.713

Link: CVE-2026-13198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T16:30:05Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')