CVE-2021-28660: High severity linux kernel vulnerability
Last updated 25 April 2025
Other sources
rtwwxsetscan in drivers/staging/rtl8188eu/osdep/ioctllinux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/ (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28660?
CVE-2021-28660 is considered a moderate severity vulnerability due to potential buffer overflow risks.
How do I fix CVE-2021-28660?
To fix CVE-2021-28660, update your Linux kernel to version 5.11.7 or later.
What systems are affected by CVE-2021-28660?
CVE-2021-28660 affects various versions of the Linux kernel up to 5.11.6, including distributions like Debian and Fedora.
What impact does CVE-2021-28660 have on systems?
CVE-2021-28660 could allow an attacker to execute arbitrary code or crash the affected system.
Is CVE-2021-28660 being actively exploited?
As of now, there is no public evidence of active exploitation of CVE-2021-28660, but it is advisable to apply patches promptly.