CVE-2026-46569
EUVD-2026-9435407.10.2026, 14:17
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tuxera | ntfs-3g | 𝑥 < 2026.7.7 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| libntfs-3g-devel |
| ||||||||||
| libntfs-3g87 |
| ||||||||||
| ntfs-3g |
| ||||||||||
| ntfsprogs |
|
Common Weakness Enumeration