CVE-2026-46571
EUVD-2026-9435307.10.2026, 14:17
In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential information in ntfs-3g process memory by crafting a malicious NTFS image. The out-of-bounds read is triggered by a readlink on a corrupted file.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tuxera | ntfs-3g | 𝑥 < 2026.7.7 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| libntfs-3g-devel |
| ||||||||||
| libntfs-3g87 |
| ||||||||||
| ntfs-3g |
| ||||||||||
| ntfsprogs |
|
Common Weakness Enumeration