CVE-2026-13198: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in KUNBUS piControl
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to corrupt kernel heap and event-list state and disclose a small amount of adjacent kernel memory, resulting in kernel memory corruption and denial of service, by issuing concurrent crafted requests from multiple threads through the piControl character device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13198?
CVE-2026-13198 has a severity score of 52.
How do I fix CVE-2026-13198?
To fix CVE-2026-13198, update KUNBUS piControl to the latest version that addresses this race condition vulnerability.
What type of vulnerability is CVE-2026-13198?
CVE-2026-13198 is classified as a race condition vulnerability, specifically a CWE-362 issue.
Who is affected by CVE-2026-13198?
Local authenticated attackers on KUNBUS piControl version 2.6.2 are affected by CVE-2026-13198.
What potential impact does CVE-2026-13198 have?
CVE-2026-13198 can allow attackers to corrupt the kernel heap, leading to potential system instability.