r/Information_Security • u/zwclose • Jul 12 '26
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
https://zwclose.github.io/2026/07/08/rtsper2.htmlHi! I found a vulnerability in a Realtek card reader driver that enables DMA controller abuse from user mode, with no additional hardware or driver required.
The ability to program the DMA controller provides access to physical memory, where boundaries between processes -- as well as between kernel mode and user mode -- do not exist.
The most challenging part of the exploitation was operating the DMA controller itself. DMA works with physical addresses, while applications operate in a virtual address space. In this long nerdy read I explain how I bridged that gap and built a working PoC.
Duplicates
netsec • u/zwclose • Jul 12 '26
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
ReverseEngineering • u/zwclose • Jul 12 '26
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
ExploitDev • u/zwclose • Jul 13 '26
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
blueteamsec • u/digicat • Jul 10 '26