Heap-based buffer overflow in NTFS-3G - CVE-2026-40706

 

Heap-based buffer overflow in NTFS-3G - CVE-2026-40706

Published: April 28, 2026


Vulnerability identifier: #VU128272
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40706
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in ntfs_build_permissions_posix(). A local user can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

NTFS-3G
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Development Tools Module
Basesystem Module
openEuler
Anolis OS
ntfs-3g
ntfs-3g-debuginfo
ntfs-3g-debugsource
ntfs-3g-devel
ntfs-3g-help
ntfsprogs
ntfs-3g_ntfsprogs-debugsource
ntfs-3g_ntfsprogs-debuginfo
ntfsprogs-debuginfo
libntfs-3g-devel
libntfs-3g87-debuginfo
libntfs-3g87
ntfs-3g (Debian package)
ntfs-3g-libs
ntfs-3g-doc

How to mitigate CVE-2026-40706

Install updates from vendor's website.

NTFS-3G - update to 2026.2.25
ntfs-3g - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-debuginfo - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-debugsource - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-devel - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-help - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfsprogs - update to 2022.5.17-150000.3.24.1
ntfs-3g_ntfsprogs-debugsource - update to 2022.5.17-150000.3.24.1
ntfs-3g - update to 2022.5.17-150000.3.24.1
ntfs-3g_ntfsprogs-debuginfo - update to 2022.5.17-150000.3.24.1
ntfsprogs-debuginfo - update to 2022.5.17-150000.3.24.1
libntfs-3g-devel - update to 2022.5.17-150000.3.24.1
libntfs-3g87-debuginfo - update to 2022.5.17-150000.3.24.1
libntfs-3g87 - update to 2022.5.17-150000.3.24.1
ntfs-3g-debuginfo - update to 2022.5.17-150000.3.24.1
ntfs-3g (Debian package) - addressed in versions 1:2022.10.3-1+deb12u3, 1:2022.10.3-5+deb13u1
ntfs-3g - update to 2022.10.3-10.el10_2
ntfsprogs - update to 2026.2.25-1
ntfs-3g - update to 2026.2.25-1
ntfs-3g-devel - update to 2026.2.25-1
ntfs-3g-libs - update to 2026.2.25-1
ntfs-3g-doc - update to 2026.2.25-1

External References

Related Security Bulletins