Logo
componentntfs-3g
Name
ntfs-3g
Version
2022.10.
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:tuxera:ntfs-3g:2022.10.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
2022.10.3-r1

Patches#


#
Title
Author
Resolve
1
Patch #1
Unknown

Vulnerabilities#


Name
Analysis
Description
Exploitable
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.