Race Condition Vulnerability in KUNBUS piControl by Nozomi Networks Labs
CVE-2026-13197
7.3HIGH
What is CVE-2026-13197?
A race condition vulnerability has been identified in KUNBUS piControl, specifically within its configuration and process-image management functionalities. This flaw allows a local authenticated attacker to manipulate concurrent crafted requests via the piControl character device, leading to use-after-free and invalid pointer dereference issues on kernel configuration objects. The consequences of this vulnerability include potential kernel memory corruption and denial of service, highlighting significant risks to system stability and security.
Affected Version(s)
piControl 0 <= 2.6.2
References
CVSS V4
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Quagliarella at Nozomi Networks
