{
  "document": {
    "acknowledgments": [
      {
        "organization": "CERT@VDE",
        "summary": "coordination",
        "urls": [
          "https://certvde.com"
        ]
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-GB",
    "notes": [
      {
        "category": "summary",
        "text": "The Linux kernel used in the IndustrialPI, 'linux-image-revpi-v8', prior to version 6.12.91-revpi0-rpi-v8 contains multiple vulnerabilities. Successful exploitation of these vulnerabilities can give an attacker full control over the device.",
        "title": "Summary"
      },
      {
        "category": "description",
        "text": "Authenticated users with the ability to execute their own code on the device can exploit these vulnerabilities for a local privilege escalation.",
        "title": "Impact"
      },
      {
        "category": "description",
        "text": "Ensure that only trusted code is executed on the device.",
        "title": "General Recommendations"
      },
      {
        "category": "description",
        "text": "* Please visit the Pilz website (https://www.pilz.com/en-INT/search) and download 'Firmware IndustrialPI OS 15.06.2026' in order to install the new version of the firmware on to your device.\n* Update kernel package linux-image-revpi-v8 to version 6.12.91-revpi0-rpi-v8 or higher.",
        "title": "Remediation"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "security@pilz.com",
      "name": "Pilz GmbH & Co. KG",
      "namespace": "https://www.pilz.com"
    },
    "references": [
      {
        "category": "external",
        "summary": "For further security-related issues in Pilz products please contact the Pilz Product Security Incident Response Team (PSIRT)",
        "url": "https://www.pilz.com/security"
      },
      {
        "category": "external",
        "summary": "CERT@VDE Security Advisories for Pilz GmbH & Co. KG",
        "url": "https://certvde.com/en/advisories/vendor/pilz/"
      },
      {
        "category": "self",
        "summary": "PPSA-2026-003: Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI - HTML",
        "url": "https://certvde.com/en/advisories/VDE-2026-072/"
      },
      {
        "category": "self",
        "summary": "PPSA-2026-003: Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI - CSAF",
        "url": "https://pilz.csaf-tp.certvde.com/.well-known/csaf/white/2026/ppsa-2026-003.json"
      }
    ],
    "title": "Pilz: Multiple Vulnerabilities affecting industrial PC IndustrialPI",
    "tracking": {
      "aliases": [
        "VDE-2026-072",
        "PPSA-2026-003"
      ],
      "current_release_date": "2026-08-04T10:00:00.000Z",
      "generator": {
        "date": "2026-07-29T12:57:12.630Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.6"
        }
      },
      "id": "PPSA-2026-003",
      "initial_release_date": "2026-08-04T10:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-08-04T10:00:00.000Z",
          "number": "1.0.0",
          "summary": "Initial Version"
        }
      ],
      "status": "final",
      "version": "1.0.0"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:all/*",
                    "product": {
                      "name": "IndustrialPI 4",
                      "product_id": "CSAFPID-11000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:h:pilz:industrialpi_4:*:*:*:*:*:*:*:*",
                        "model_numbers": [
                          "A1000002",
                          "A1000003"
                        ]
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "IndustrialPI 4"
              }
            ],
            "category": "product_family",
            "name": "Hardware"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "vers:generic/10.06.2025",
                    "product": {
                      "name": "IndustrialPI OS 10.06.2025",
                      "product_id": "CSAFPID-21000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:10.06.2025:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "vers:generic/23.06.2025",
                    "product": {
                      "name": "IndustrialPI OS 23.06.2025",
                      "product_id": "CSAFPID-21001",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:23.06.2025:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "vers:generic/25.12.2025",
                    "product": {
                      "name": "IndustrialPI OS 25.12.2025",
                      "product_id": "CSAFPID-21002",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:25.12.2025:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "vers:generic/15.06.2026",
                    "product": {
                      "name": "IndustrialPI OS 15.06.2026",
                      "product_id": "CSAFPID-22000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:15.06.2026:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "IndustrialPI OS"
              }
            ],
            "category": "product_family",
            "name": "Firmware"
          }
        ],
        "category": "vendor",
        "name": "Pilz"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "vers:deb/>=6.6.0-revpi8-rpi-v8|<6.12.91-revpi0-rpi-v8",
                    "product": {
                      "name": "linux-image-revpi-v8 < 6.12.91-revpi0-rpi-v8",
                      "product_id": "CSAFPID-51000"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "vers:deb/6.12.91-revpi0-rpi-v8",
                    "product": {
                      "name": "linux-image-revpi-v8 6.12.91-revpi0-rpi-v8",
                      "product_id": "CSAFPID-52000"
                    }
                  }
                ],
                "category": "product_name",
                "name": "linux-image-revpi-v8"
              }
            ],
            "category": "product_family",
            "name": "Software"
          }
        ],
        "category": "vendor",
        "name": "Kunbus"
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "IndustrialPI OS 10.06.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-31000",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:10.06.2025:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21000",
        "relates_to_product_reference": "CSAFPID-11000"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "IndustrialPI OS 23.06.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-31001",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:23.06.2025:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21001",
        "relates_to_product_reference": "CSAFPID-11000"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "IndustrialPI OS 25.12.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-31002",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:25.12.2025:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-21002",
        "relates_to_product_reference": "CSAFPID-11000"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-revpi-v8 < 6.12.91-revpi0-rpi-v8 default component of IndustrialPI OS 10.06.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-31003"
        },
        "product_reference": "CSAFPID-51000",
        "relates_to_product_reference": "CSAFPID-31000"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-revpi-v8 < 6.12.91-revpi0-rpi-v8 default component of IndustrialPI OS 23.06.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-31004"
        },
        "product_reference": "CSAFPID-51000",
        "relates_to_product_reference": "CSAFPID-31001"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-revpi-v8 < 6.12.91-revpi0-rpi-v8 default component of IndustrialPI OS 25.12.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-31005"
        },
        "product_reference": "CSAFPID-51000",
        "relates_to_product_reference": "CSAFPID-31002"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "IndustrialPI OS 15.06.2026 installed on IndustrialPI 4",
          "product_id": "CSAFPID-32000",
          "product_identification_helper": {
            "cpe": "cpe:2.3:o:pilz:industrialpi_firmware:15.06.2026:*:*:*:*:*:*:*"
          }
        },
        "product_reference": "CSAFPID-22000",
        "relates_to_product_reference": "CSAFPID-11000"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "linux-image-revpi-v8 6.12.91-revpi0-rpi-v8 installed on IndustrialPI OS 10.06.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-32001"
        },
        "product_reference": "CSAFPID-52000",
        "relates_to_product_reference": "CSAFPID-31000"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "linux-image-revpi-v8 6.12.91-revpi0-rpi-v8 installed on IndustrialPI OS 23.06.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-32002"
        },
        "product_reference": "CSAFPID-52000",
        "relates_to_product_reference": "CSAFPID-31001"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "linux-image-revpi-v8 6.12.91-revpi0-rpi-v8 installed on IndustrialPI OS 25.12.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-32003"
        },
        "product_reference": "CSAFPID-52000",
        "relates_to_product_reference": "CSAFPID-31002"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "linux-image-revpi-v8 6.12.91-revpi0-rpi-v8 default component of IndustrialPI OS 25.12.2025 installed on IndustrialPI 4",
          "product_id": "CSAFPID-32004"
        },
        "product_reference": "CSAFPID-52000",
        "relates_to_product_reference": "CSAFPID-32000"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-31431",
      "cwe": {
        "id": "CWE-669",
        "name": "Incorrect Resource Transfer Between Spheres"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. ",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004"
        ],
        "known_affected": [
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update kernel package linux-image-revpi-v8 to version 6.12.91-revpi0-rpi-v8 or higher.",
          "product_ids": [
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to Firmware IndustrialPI OS 17.06.2026 or later.",
          "product_ids": [
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "modifiedAttackComplexity": "LOW",
            "modifiedAttackVector": "LOCAL",
            "modifiedAvailabilityImpact": "HIGH",
            "modifiedConfidentialityImpact": "HIGH",
            "modifiedIntegrityImpact": "HIGH",
            "modifiedPrivilegesRequired": "LOW",
            "modifiedScope": "UNCHANGED",
            "modifiedUserInteraction": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ],
      "title": "crypto: algif_aead - Revert to operating out-of-place"
    },
    {
      "cve": "CVE-2026-43284",
      "cwe": {
        "id": "CWE-123",
        "name": "Write-what-where Condition"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv6 datagram append paths did not set this flag when splicing pages into UDP skbs. That leaves an ESP-in-UDP packet made from shared pipe pages looking like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW fast path for uncloned skbs without a frag_list and decrypts in place over data that is not owned privately by the skb. Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching TCP. Also make ESP input fall back to skb_cow_data() when the flag is present, so ESP does not decrypt externally backed frags in place. Private nonlinear skb frags still use the existing fast path. This intentionally does not change ESP output. In esp_output_head(), the path that appends the ESP trailer to existing skb tailroom without calling skb_cow_data() is not reachable for nonlinear skbs: skb_tailroom() returns zero when skb->data_len is nonzero, while ESP tailen is positive. Thus ESP output will either use the separate destination-frag path or fall back to skb_cow_data(). ",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004"
        ],
        "known_affected": [
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update kernel package linux-image-revpi-v8 to version 6.12.91-revpi0-rpi-v8 or higher.",
          "product_ids": [
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to Firmware IndustrialPI OS 17.06.2026 or later.",
          "product_ids": [
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "modifiedAttackComplexity": "LOW",
            "modifiedAttackVector": "LOCAL",
            "modifiedAvailabilityImpact": "HIGH",
            "modifiedConfidentialityImpact": "HIGH",
            "modifiedIntegrityImpact": "HIGH",
            "modifiedPrivilegesRequired": "LOW",
            "modifiedScope": "CHANGED",
            "modifiedUserInteraction": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ],
      "title": "xfrm: esp: avoid in-place decrypt on shared skb frags"
    },
    {
      "cve": "CVE-2026-46300",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by later in-place writers. In particular, ESP input checks skb_has_shared_frag() before deciding whether an uncloned nonlinear skb can skip skb_cow_data(). If TCP receive coalescing has moved shared frags into an unmarked skb, ESP can see skb_has_shared_frag() as false and decrypt in place over page-cache backed frags. Propagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged frags. The tailroom copy path does not need the marker because it copies bytes into @to's linear data rather than transferring frag descriptors. ",
          "title": "CVE Description"
        }
      ],
      "product_status": {
        "fixed": [
          "CSAFPID-32001",
          "CSAFPID-32002",
          "CSAFPID-32003",
          "CSAFPID-32004"
        ],
        "known_affected": [
          "CSAFPID-31003",
          "CSAFPID-31004",
          "CSAFPID-31005"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Update kernel package linux-image-revpi-v8 to version 6.12.91-revpi0-rpi-v8 or higher.",
          "product_ids": [
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Update to Firmware IndustrialPI OS 17.06.2026 or later.",
          "product_ids": [
            "CSAFPID-31000",
            "CSAFPID-31001",
            "CSAFPID-31002"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "modifiedAttackComplexity": "LOW",
            "modifiedAttackVector": "LOCAL",
            "modifiedAvailabilityImpact": "HIGH",
            "modifiedConfidentialityImpact": "HIGH",
            "modifiedIntegrityImpact": "HIGH",
            "modifiedPrivilegesRequired": "LOW",
            "modifiedScope": "UNCHANGED",
            "modifiedUserInteraction": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-31003",
            "CSAFPID-31004",
            "CSAFPID-31005"
          ]
        }
      ],
      "title": "net: skbuff: preserve shared-frag marker during coalescing"
    }
  ]
}