Skip to main content Skip to page footer

27.07.2026

Kunbus-2026-0000008: Multiple Vulnerabilities in piControl Kernel Module

TLP: AMBER

Publisher: KUNBUS PSIRT Document category: csaf_security_advisory
Initial release date: 2026-07-27T08:01:00.000Z Engine: csaf-cms-backend 1.0.0-kunbus.1
Current release date: 2026-07-27T08:01:00.000Z Build Date: 2026-07-17T13:00:37.289Z
Current version: 1.0.0 Status: final
CVSSv3.1 Base Score: 7.8 Severity:
Original language: Language: en-US
Also referred to:

Vulnerabilities

Array index out of bounds read in picontrol kernel module (CVE-2026-13196)

Array Out of Bounds Write in piControl Kernel module.

An authenticated User can modify the piControl config file to trigger an Array Out of Bounds Write. The config file is used to control the piControl Kernel Module which causes the vulnerability end up in kernel space.

CWE: CWE-787:Out-of-bounds Write

Product status

Known affected
Product CVSS-Vector CVSS Base Score
KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C 7.8
Fixed
  • KUNBUS picontrol vers:deb 2.7.0-1+deb13+1

Remediations

Vendor fix (2026-07-17T10:00:00.000Z)

Upgrade to picontrol version 2.7.0

For products:
  • KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1

https://packages.revolutionpi.com/pool/main/p/picontrol/picontrol_2.7.0-1+deb13+1_arm64.deb

Acknowledgments

  • Gabriele Quagliarella from Nozomi Networks

References

Race Condition in piControl Kernel module (CVE-2026-13197)

TOCTOU in piControl

A race condition in piControl Kernel module can lead to storage freed and reused while the original user is still waiting resulting in possible data corruption.

CWE: CWE-362:Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Product status

Known affected
Product CVSS-Vector CVSS Base Score
KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C 7
Fixed
  • KUNBUS picontrol vers:deb 2.7.0-1+deb13+1

Remediations

Vendor fix (2026-07-17T10:00:00.000Z)

Upgrade to picontrol version 2.7.0

For products:
  • KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1

https://packages.revolutionpi.com/pool/main/p/picontrol/picontrol_2.7.0-1+deb13+1_arm64.deb

Acknowledgments

  • Gabriele Quagliarella from Nozomi Networks

References

Race Condition with possible internal datastructure corruption (CVE-2026-13198)

Possible internal datastructure corruption

Race condition i event wakeup can corrupt the eventList used to manage those wakeup call.

CWE: CWE-362:Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Product status

Known affected
Product CVSS-Vector CVSS Base Score
KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H/E:P/RL:O/RC:C 6.5
KUNBUS picontrol vers:deb 2.7.0-1+deb13+1 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H/E:P/RL:O/RC:C 6.5
Fixed
  • KUNBUS picontrol vers:deb 2.8.0-1+deb13+1

Remediations

Vendor fix (2026-07-17T10:00:00.000Z)

Upgrade to picontrol version 2.8.0

For products:
  • KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1
  • KUNBUS picontrol vers:deb 2.7.0-1+deb13+1

https://packages.revolutionpi.com/pool/main/p/picontrol/picontrol_2.8.0-1+deb13+1_arm64.deb

Acknowledgments

  • Gabriele Quagliarella from Nozomi Networks

References

KUNBUS PSIRT

Namespace: https://www.kunbus.com

product-security@kunbus.com

KUNBUS GmbH develops and produces the Revolution Pi Family, Revolution Pi OS and the extension modules for RevPi amongst others. KUNBUS PSIRT is responsible for vulnerability handling across all KUNBUS products and services.

References

Revision history

Version Date of the revision Summary of the revision
1.0.0 2026-07-27T08:01:00.000Z Initial Publication

Sharing rules

TLP:AMBER
For the TLP version see: https://www.first.org/tlp/

Legal Disclaimer

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. KUNBUS RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Kontakt