CVE-2026-40706

EUVD-2026-24467
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mitreCNA
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
tuxerantfs-3g
2022.10.3 ≤
𝑥
< 2026.2.25
CNA
Debian logo
Debian Releases
Debian Product
Codename
ntfs-3g
bookworm
1:2022.10.3-1+deb12u3
fixed
bookworm (security)
1:2022.10.3-1+deb12u3
fixed
bullseye
vulnerable
bullseye (security)
1:2017.3.23AR.3-4+deb11u5
fixed
forky
1:2026.2.25-1
fixed
sid
1:2026.2.25-1
fixed
trixie
1:2022.10.3-5+deb13u1
fixed
trixie (security)
1:2022.10.3-5+deb13u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libntfs-3g-devel
suse enterprise server 15 SP6
2022.5.17-150000.3.24.1
fixed
libntfs-3g87
suse enterprise desktop 15 SP7
2022.5.17-150000.3.24.1
fixed
suse enterprise sap 15 SP7
2022.5.17-150000.3.24.1
fixed
suse enterprise server 15 SP6
2022.5.17-150000.3.24.1
fixed
suse enterprise server 15 SP7
2022.5.17-150000.3.24.1
fixed
ntfs-3g
suse enterprise desktop 15 SP7
2022.5.17-150000.3.24.1
fixed
suse enterprise sap 15 SP7
2022.5.17-150000.3.24.1
fixed
suse enterprise server 15 SP6
2022.5.17-150000.3.24.1
fixed
suse enterprise server 15 SP7
2022.5.17-150000.3.24.1
fixed
ntfsprogs
suse enterprise desktop 15 SP7
2022.5.17-150000.3.24.1
fixed
suse enterprise sap 15 SP7
2022.5.17-150000.3.24.1
fixed
suse enterprise server 15 SP6
2022.5.17-150000.3.24.1
fixed
suse enterprise server 15 SP7
2022.5.17-150000.3.24.1
fixed