Multiple Vulnerabilities in the piControl Kernel Module & in KUNBUS Packages for Revolution Pi – Install Updates Now

Take a look inside and be the first to get news regarding Revolution Pi
Post Reply
User avatar
silke4revpi
KUNBUS
Posts: 16
Joined: 11 Nov 2025, 09:50

Multiple Vulnerabilities in the piControl Kernel Module & in KUNBUS Packages for Revolution Pi – Install Updates Now

Post by silke4revpi »

We've released patched packages for RevPi Trixie and RevPi Bookworm that close several security vulnerabilities in KUNBUS packages for Revolution Pi (CVE-2026-57469, CVE-2026-57471, CVE-2026-57472) as well as in the piControl kernel module (CVE-2026-13196, CVE-2026-13197, CVE-2026-13198). We recommend installing the updates promptly. You can find the full security advisories here: KUNBUS-2026-0000009 and KUNBUS-2026-0000008.

How to Install Updates
You can find step-by-step instructions for updating your RevPi devices here in our documentation.

About the Vulnerabilities
AI-powered analysis is drastically accelerating the search for software vulnerabilities – not just in the Linux kernel, but in other software components as well. That security gaps are being identified and closed is all in all a positive development: every patch makes the system more secure. We will keep you up to date about further developments via our Update Tracker.

CVE-2026-57469 is a CSRF vulnerability in the PiCtory web configuration tool that could allow an attacker to take over a logged-in session. Fixed in PiCtory 2.17.0.

CVE-2026-57471 allows an attacker with access to the revpipyload XML-RPC interface to read files outside the working directory with the rights of the default user. Fixed in revpipyload 0.11.1.

CVE-2026-57472 allows a locally authenticated attacker with access to the revpipyload XML-RPC interface to delete files outside the working directory with the rights of the default user. Fixed in revpipyload 0.11.1.

CVE-2026-13196 is an out-of-bounds write vulnerability in the piControl kernel module that can be triggered by a manipulated piControl config file. Fixed in piControl 2.7.0.

CVE-2026-13197 is a race condition in the piControl kernel module that can lead to data corruption. Fixed in piControl 2.7.0.

CVE-2026-13198 is another race condition in the piControl kernel module that can corrupt internal data structures during event wakeup. Fixed in piControl 2.8.0.

Full Security Advisories
Questions or Issues?
Our team is happy to help you here in the forum.

📢 Would you like to be notified about our software updates by email in the future?
Subscribe now to the RevPi Update Tracker.

Best regards
Your Revolution Pi Team
Post Reply