Impact
KUNBUS piControl contains a race condition in its event notification subsystem that allows a local authenticated user to trigger concurrent crafted requests through the piControl character device. The improper synchronization between threads can corrupt the kernel heap and the event-list state, leading to disclosure of a small portion of adjacent kernel memory, overall kernel memory corruption, and a denial of service in the form of a system crash or reboot.
Affected Systems
The vulnerability exists in KUNBUS piControl version 2.6.2. No other affected versions or components are listed in the available data.
Risk and Exploitability
The CVSS score of 5.9 places the vulnerability in the medium severity range, and exploitation requires a local authenticated attacker who can issue concurrent requests. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. Given these constraints, the likelihood of widespread exploitation is moderate; an attacker would need sufficient local privileges and the ability to generate parallel requests against the piControl device to trigger the fault.
OpenCVE Enrichment