Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4544-1 | ntfs-3g security update |
Debian DSA |
DSA-6221-1 | ntfs-3g security update |
Wed, 22 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NTFS-3G SUID-root Heap Buffer Overflow Enables Privilege Escalation |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs. | |
| First Time appeared |
Tuxera
Tuxera ntfs-3g |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:2.3:a:tuxera:ntfs-3g:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tuxera
Tuxera ntfs-3g |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-22T15:35:30.245Z
Reserved: 2026-04-15T00:00:00.000Z
Link: CVE-2026-40706
Updated: 2026-04-21T21:20:00.477Z
Status : Awaiting Analysis
Published: 2026-04-21T22:16:19.077
Modified: 2026-04-22T21:23:52.620
Link: CVE-2026-40706
No data.
OpenCVE Enrichment
Updated: 2026-04-22T07:00:12Z
Debian DLA
Debian DSA