Logo
vulnerabilityCVE-2026-40706
Name
CVE-2026-40706
Source
NVD ( link)Debian ( link)
Description
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
ntfs-3g
Exploitable

Vulnerability Ratings#


8.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2026.7.7
Not Affected
buildroot
master
2026.7.7
Not Affected
openwrt
master
2022.10.3-r1
Exploitable
yocto
kirkstone
2022.10.3
Exploitable
yocto
master
2026.7.7
Not Affected
yocto
scarthgap
2022.10.3
Exploitable