CVE Vulnerabilities

CVE-2021-39251

NULL Pointer Dereference

Published: Sep 07, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Ntfs-3g Tuxera * 2021.8.22 (excluding)
Ntfs-3g Ubuntu bionic *
Ntfs-3g Ubuntu devel *
Ntfs-3g Ubuntu esm-infra/xenial *
Ntfs-3g Ubuntu focal *
Ntfs-3g Ubuntu hirsute *
Ntfs-3g Ubuntu impish *
Ntfs-3g Ubuntu jammy *
Ntfs-3g Ubuntu trusty *
Ntfs-3g Ubuntu trusty/esm *
Ntfs-3g Ubuntu xenial *
Advanced Virtualization for RHEL 8.2.1 RedHat virt:8.2-8020120210917153657.863bb0db *
Advanced Virtualization for RHEL 8.2.1 RedHat virt-devel:8.2-8020120210917153657.863bb0db *
Advanced Virtualization for RHEL 8.4.0.Z RedHat virt:av-8040020210922084349.522a0ee4 *
Advanced Virtualization for RHEL 8.4.0.Z RedHat virt-devel:av-8040020210922084349.522a0ee4 *
Red Hat Enterprise Linux 8 RedHat virt-devel:rhel-8060020220408104655.d63f516d *
Red Hat Enterprise Linux 8 RedHat virt:rhel-8060020220408104655.d63f516d *

Potential Mitigations

References