First published: Thu Aug 26 2021(Updated: )
A NULL pointer dereference flaw was found in btrfs_rm_device function in fs/btrfs/volumes.c in Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This could allow a local attacker to crash the system or leak kernel internal information. References: <a href="https://lore.kernel.org/linux-btrfs/CAFcO6XO5TC5sEo-C9JGC75JkNAzkOSSLA3a=bwQqXFFbRTZ7Gw@mail.gmail.com/T/#md4b850f33616b7364f86e6fed144abc925f3669c">https://lore.kernel.org/linux-btrfs/CAFcO6XO5TC5sEo-C9JGC75JkNAzkOSSLA3a=bwQqXFFbRTZ7Gw@mail.gmail.com/T/#md4b850f33616b7364f86e6fed144abc925f3669c</a> <a href="https://lore.kernel.org/linux-btrfs/20210806102415.304717-1-wqu@suse.com/T/#u">https://lore.kernel.org/linux-btrfs/20210806102415.304717-1-wqu@suse.com/T/#u</a>
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.13-1 | |
Linux Kernel | <=5.14.20 | |
Fedora | =34 | |
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
netapp h410c firmware | ||
netapp h410c | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h300e firmware | ||
netapp h300e | ||
All of | ||
netapp h500e firmware | ||
netapp h500e | ||
All of | ||
netapp h700e firmware | ||
netapp h700e | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h300s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h500s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h700s | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h300e | ||
netapp baseboard management controller h500e firmware | ||
netapp baseboard management controller h500e | ||
netapp baseboard management controller h700e firmware | ||
netapp baseboard management controller h700e | ||
NetApp Baseboard Management Controller Firmware | ||
netapp baseboard management controller h410s | ||
netapp baseboard management controller h410c firmware | ||
netapp baseboard management controller h410c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3739 has a severity level that allows local attackers to crash the system or potentially leak sensitive kernel information.
To fix CVE-2021-3739, it is recommended to upgrade to a patched version of the Linux kernel, specifically 5.10.223-1, 5.10.226-1, or later.
CVE-2021-3739 affects users running vulnerable Linux kernel versions up to 5.14.20 and certain NetApp firmware versions.
CVE-2021-3739 is caused by a NULL pointer dereference flaw in the btrfs_rm_device function within the Linux kernel.
CVE-2021-3739 cannot be exploited remotely as it requires local access with CAP_SYS_ADMIN capabilities.