CVE-2026-46570
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:08:16
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by ...
CVE-2026-46572
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:08:27
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by crea...
CVE-2026-46571
- EPSS 0.13%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:08:32
In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds ...
CVE-2026-46569
- EPSS 0.16%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 09.10.2026 14:17:21
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by e...
CVE-2026-42618
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:09:07
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by r...
CVE-2026-42617
- EPSS 0.15%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:09:12
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a direct...
CVE-2026-42616
- EPSS 0.16%
- Veröffentlicht 07.10.2026 00:00:00
- Zuletzt bearbeitet 08.10.2026 19:09:18
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a malicious NTFS image. The overflow is triggered by reading a file.
CVE-2026-40706
- EPSS 0.17%
- Veröffentlicht 21.04.2026 00:00:00
- Zuletzt bearbeitet 22.04.2026 21:23:52
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is trigge...
CVE-2022-40284
- EPSS 0.37%
- Veröffentlicht 06.11.2022 23:15:09
- Zuletzt bearbeitet 02.05.2025 19:15:53
A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS...
CVE-2022-30789
- EPSS 0.44%
- Veröffentlicht 26.05.2022 16:15:09
- Zuletzt bearbeitet 02.12.2025 21:15:50
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.