Wind River Support Network

HomeDefectsLIN10-8389
Fixed

LIN10-8389 : Security Advisory - linux - CVE-2021-28660

Created: Mar 17, 2021    Updated: Apr 1, 2021
Resolved Date: Apr 1, 2021
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Kernel

Description

rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=74b6b20df8cfe90ada777d621b54c32e69e27cd7

CREATE(Triage):(User=admin) [CVE-2021-28660|https://nvd.nist.gov/vuln/detail/CVE-2021-28660]

CVEs


Live chat
Online