CVE Vulnerabilities

CVE-2021-39251

NULL Pointer Dereference

Published: Sep 07, 2021 | Modified: Dec 02, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Ntfs-3gTuxera*2021.8.22 (excluding)
Advanced Virtualization for RHEL 8.2.1RedHatvirt:8.2-8020120210917153657.863bb0db*
Advanced Virtualization for RHEL 8.2.1RedHatvirt-devel:8.2-8020120210917153657.863bb0db*
Advanced Virtualization for RHEL 8.4.0.ZRedHatvirt:av-8040020210922084349.522a0ee4*
Advanced Virtualization for RHEL 8.4.0.ZRedHatvirt-devel:av-8040020210922084349.522a0ee4*
Red Hat Enterprise Linux 8RedHatvirt-devel:rhel-8060020220408104655.d63f516d*
Red Hat Enterprise Linux 8RedHatvirt:rhel-8060020220408104655.d63f516d*
Ntfs-3gUbuntubionic*
Ntfs-3gUbuntudevel*
Ntfs-3gUbuntuesm-infra-legacy/trusty*
Ntfs-3gUbuntuesm-infra/bionic*
Ntfs-3gUbuntuesm-infra/focal*
Ntfs-3gUbuntuesm-infra/xenial*
Ntfs-3gUbuntufocal*
Ntfs-3gUbuntuhirsute*
Ntfs-3gUbuntuimpish*
Ntfs-3gUbuntujammy*
Ntfs-3gUbuntutrusty*
Ntfs-3gUbuntutrusty/esm*
Ntfs-3gUbuntuxenial*

Potential Mitigations

References