THREATOPS
THREAT OPSThreat News › Realtek edimax 52fc10d19 In-Band Ioctl Response Length Confusion Causes Heap Buffer Overflow

Realtek edimax 52fc10d19 In-Band Ioctl Response Length Confusion Causes Heap Buffer Overflow

lowfulldisclosurePublished 2026-08-26

<p>Posted by Ron E on Aug 26</p>The Realtek in-band ioctl bridge contains a heap-buffer overflow when<br /> processing peer-supplied ioctl response data.<br /> <br /> inband_ioctl() receives a response through the Realtek in-band transport<br /> and extracts a 32-bit data_get_len value from that response. For several<br /> wireless &quot;get&quot; operations, this peer-controlled value is subseque

Original source: https://seclists.org/fulldisclosure/2026/Aug/105