Heap-based buffer overflow in NTFS-3G - CVE-2026-40706
Published: April 28, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in ntfs_build_permissions_posix(). A local user can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Debian Linux
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Development Tools Module
Basesystem Module
openEuler
Anolis OS
ntfs-3g
ntfs-3g-debuginfo
ntfs-3g-debugsource
ntfs-3g-devel
ntfs-3g-help
ntfsprogs
ntfs-3g_ntfsprogs-debugsource
ntfs-3g_ntfsprogs-debuginfo
ntfsprogs-debuginfo
libntfs-3g-devel
libntfs-3g87-debuginfo
libntfs-3g87
ntfs-3g (Debian package)
ntfs-3g-libs
ntfs-3g-doc
How to mitigate CVE-2026-40706
ntfs-3g - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-debuginfo - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-debugsource - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-devel - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfs-3g-help - addressed in versions 2022.5.17-4, 2022.10.3-3
ntfsprogs - update to 2022.5.17-150000.3.24.1
ntfs-3g_ntfsprogs-debugsource - update to 2022.5.17-150000.3.24.1
ntfs-3g - update to 2022.5.17-150000.3.24.1
ntfs-3g_ntfsprogs-debuginfo - update to 2022.5.17-150000.3.24.1
ntfsprogs-debuginfo - update to 2022.5.17-150000.3.24.1
libntfs-3g-devel - update to 2022.5.17-150000.3.24.1
libntfs-3g87-debuginfo - update to 2022.5.17-150000.3.24.1
libntfs-3g87 - update to 2022.5.17-150000.3.24.1
ntfs-3g-debuginfo - update to 2022.5.17-150000.3.24.1
ntfs-3g (Debian package) - addressed in versions 1:2022.10.3-1+deb12u3, 1:2022.10.3-5+deb13u1
ntfs-3g - update to 2022.10.3-10.el10_2
ntfsprogs - update to 2026.2.25-1
ntfs-3g - update to 2026.2.25-1
ntfs-3g-devel - update to 2026.2.25-1
ntfs-3g-libs - update to 2026.2.25-1
ntfs-3g-doc - update to 2026.2.25-1
External References
Related Security Bulletins
- Heap-based buffer overflow in NTFS-3G
- openEuler 24.03 LTS update for ntfs-3g
- openEuler 22.03 LTS SP4 update for ntfs-3g
- openEuler 20.03 LTS SP4 update for ntfs-3g
- openEuler 24.03 LTS SP3 update for ntfs-3g
- openEuler 24.03 LTS SP1 update for ntfs-3g
- SUSE update for ntfs-3g_ntfsprogs
- Debian update for ntfs-3g
- Anolis OS update for ntfs-3g
- Fedora EPEL 10.2 update for ntfs-3g