SB2026093088 - Multiple vulnerabilities in NTFS-3G
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the ntfs_ie_add_vcn() function within the libntfs-3g/index.c file. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.
2) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the ntfs_acl_owner() function. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.
3) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the ntfs_acl_owner() function. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.
4) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to a boundary error in the ntfs_same_sid() function. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and gain access to sensitive information or perform a denial of service (DoS) attack.
5) Infinite loop (CVE-ID: N/A)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in the ntfs_inode_attach_all_extents() function. A local attacker can consume all available system resources and cause denial of service conditions.
6) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the ntfs_check_restart_area() function. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.
7) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to compromsie the target system.
The vulnerability exists due to a boundary error in the ntfs_ea_check_wsldev() function. A local attacker can cause leakage of heap data outside the memory allocation.
8) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the ntfs_external_attr_find() function within libntfs-3g/attrib.c file. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause a denial of service condition on the target system.
9) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 2.1 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to a boundary error in the ntfs_mapping_pairs_decompress_i() function in runlist.c file. A local attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and cause subsequent read and write operations to access unintended locations.
Remediation
Install update from vendor's website.
References
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r6xj-6488-p8mv
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-pc48-m7cx-qf72
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-x98j-3g35-f59x
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-jcjj-9262-6j6p
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-xrvx-6jrp-4q3x
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-2c97-47cr-9xr8
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-wf3w-fjjg-x4w3
- https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-mc3c-983p-wqm8