CVE-2026-36355 affects the rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK, in all known versions through v3.4.14B. The driver exposes debug ioctl handlers write_mem (0x89F5) and read_mem (0x89F6) without performing access control checks. According to the provided content, these handlers are compiled into production builds because the IOCTL_DEBUG_CMD macro is unconditionally defined in 8192cd_cfg.h. As a result, an attacker able to invoke these ioctls against the vulnerable driver can directly write to or read from memory without authorization. Given that this occurs in a kernel driver, the flaw enables unauthorized access to kernel memory and potentially arbitrary kernel memory modification.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Small standalone local privilege escalation repository centered on a single C exploit, kpwn.c, with README documentation and no framework integration. The exploit targets CVE-2026-36355 in Realtek rtl819x Jungle SDK Wi-Fi drivers, where private wireless debug IOCTLs expose unauthenticated arbitrary kernel memory read/write to local users. Repository structure is minimal: README.md contains the advisory, affected products, technical root cause, and usage example; kpwn.c implements the exploit logic. Core exploit flow: it opens a socket and enumerates interfaces under /sys/class/net, probing each non-loopback interface with IOCTL 0x89F6 to identify a vulnerable Realtek-backed wireless interface. Once a working read primitive is confirmed, it resolves init_task either via symbol assistance mentioned in the README or by brute-force scanning the ARM kernel .data range 0xC0800000-0xC1000000 for the string "swapper" and validating nearby cred data. It then auto-detects task_struct field offsets (comm, cred, tasks, pid), walks the task list to find the current process, reads the cred structure, and uses IOCTL 0x89F5 to overwrite UID/GID and capability fields. Finally, it verifies privilege escalation and execs /bin/sh. Capabilities are clearly offensive and operational rather than just demonstrative: arbitrary kernel read, arbitrary kernel write, dynamic kernel structure discovery, current task discovery, credential overwrite, and root shell spawn. The exploit is not a detector and not fake; it contains working LPE logic with a hardcoded ARM kernel scan range but no hardcoded symbol addresses, making it more portable across affected OEM builds than a trivial PoC. No external C2 or remote network infrastructure is used; the attack is local and interacts only with local kernel interfaces and filesystem paths.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.