Impact
A heap buffer overflow exists in the ntfs_ib_cut_tail() function of NTFS-3G, which can corrupt heap memory when the SUID-root ntfs-3g binary processes a malicious NTFS image by creating a file in a specially crafted directory. An attacker who can supply such an image can cause the overflow and potentially execute arbitrary code with root privileges.
Affected Systems
All NTFS-3G releases before 2026.7.7, specifically the SUID-root ntfs-3g binary used for mounting NTFS volumes on Linux systems, are affected. Any installation that relies on this binary and runs it with set‑uid root could be impacted.
Risk and Exploitability
The flaw is triggered by the SUID-root ntfs-3g binary when it processes a malicious NTFS image containing a crafted directory structure and a file creation. The attack vector is likely local because the vulnerable code runs in user context but with elevated privileges. The EPSS score is not available, and the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment
Debian DSA
Ubuntu USN