CVE-2021-3739
Executive Summary
CVE-2021-3739 is a NULL pointer dereference in the Linux kernel’s btrfs_rm_device function. A local attacker with CAP_SYS_ADMIN can trigger the flaw, causing a system crash or leaking kernel data, thereby impacting availability and confidentiality. The vulnerability is not listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.1 (HIGH) - Published: 2022-03-10T17:43:01.463 - Last Modified: 2026-09-01T18:03:54.870
Original Description: A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.
"Our kindness may be the most persuasive argument for that which we believe."
— Gordon Hinckley