27.07.2026
Kunbus-2026-0000008: Multiple Vulnerabilities in piControl Kernel Module
TLP: AMBER
| Publisher: KUNBUS PSIRT | Document category: csaf_security_advisory |
| Initial release date: 2026-07-27T08:01:00.000Z | Engine: csaf-cms-backend 1.0.0-kunbus.1 |
| Current release date: 2026-07-27T08:01:00.000Z | Build Date: 2026-07-17T13:00:37.289Z |
| Current version: 1.0.0 | Status: final |
| CVSSv3.1 Base Score: 7.8 | Severity: |
| Original language: | Language: en-US |
| Also referred to: | |
Vulnerabilities
Array index out of bounds read in picontrol kernel module (CVE-2026-13196)
Array Out of Bounds Write in piControl Kernel module.An authenticated User can modify the piControl config file to trigger an Array Out of Bounds Write. The config file is used to control the piControl Kernel Module which causes the vulnerability end up in kernel space.
| CWE: | CWE-787:Out-of-bounds Write |
|---|
Product status
Known affected
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C | 7.8 |
Fixed
- KUNBUS picontrol vers:deb 2.7.0-1+deb13+1
Remediations
Vendor fix (2026-07-17T10:00:00.000Z)
Upgrade to picontrol version 2.7.0
For products:
- KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1
https://packages.revolutionpi.com/pool/main/p/picontrol/picontrol_2.7.0-1+deb13+1_arm64.deb
Acknowledgments
- Gabriele Quagliarella from Nozomi Networks
References
- Nozomi Networks security advisory NN-2026-0102 (external) https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-13196
Race Condition in piControl Kernel module (CVE-2026-13197)
TOCTOU in piControlA race condition in piControl Kernel module can lead to storage freed and reused while the original user is still waiting resulting in possible data corruption.
| CWE: | CWE-362:Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
|---|
Product status
Known affected
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C | 7 |
Fixed
- KUNBUS picontrol vers:deb 2.7.0-1+deb13+1
Remediations
Vendor fix (2026-07-17T10:00:00.000Z)
Upgrade to picontrol version 2.7.0
For products:
- KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1
https://packages.revolutionpi.com/pool/main/p/picontrol/picontrol_2.7.0-1+deb13+1_arm64.deb
Acknowledgments
- Gabriele Quagliarella from Nozomi Networks
References
- Nozomi Network Security Advisory NN-2026-0103 (external) https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-13197
Race Condition with possible internal datastructure corruption (CVE-2026-13198)
Possible internal datastructure corruptionRace condition i event wakeup can corrupt the eventList used to manage those wakeup call.
| CWE: | CWE-362:Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
|---|
Product status
Known affected
| Product | CVSS-Vector | CVSS Base Score |
|---|---|---|
| KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H/E:P/RL:O/RC:C | 6.5 |
| KUNBUS picontrol vers:deb 2.7.0-1+deb13+1 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H/E:P/RL:O/RC:C | 6.5 |
Fixed
- KUNBUS picontrol vers:deb 2.8.0-1+deb13+1
Remediations
Vendor fix (2026-07-17T10:00:00.000Z)
Upgrade to picontrol version 2.8.0
For products:
- KUNBUS picontrol vers:deb/=2.6.2-1+deb12+1
- KUNBUS picontrol vers:deb 2.7.0-1+deb13+1
https://packages.revolutionpi.com/pool/main/p/picontrol/picontrol_2.8.0-1+deb13+1_arm64.deb
Acknowledgments
- Gabriele Quagliarella from Nozomi Networks
References
- Nozomi Network Security Advisory NN-2026-0104 (external) https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-13198
KUNBUS PSIRT
Namespace: https://www.kunbus.com
product-security@kunbus.com
KUNBUS GmbH develops and produces the Revolution Pi Family, Revolution Pi OS and the extension modules for RevPi amongst others. KUNBUS PSIRT is responsible for vulnerability handling across all KUNBUS products and services.
References
- URL generated by system (self) https://psirt.kunbus.com/amber/2026/kunbus-2026-0000008.json
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1.0.0 | 2026-07-27T08:01:00.000Z | Initial Publication |
Sharing rules
TLP:AMBER
For the TLP version see: https://www.first.org/tlp/
Legal Disclaimer
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. KUNBUS RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.