Impact
A heap‑based buffer overflow exists in the build_inherited_id() function of NTFS‑3G’s security module, affecting any installation of the SUID‑root ntfs‑3g binary up to version 2026.2.25. The overflow occurs when the program attempts to process a crafted NTFS image that contains a specially designed directory and file. If triggered, the vulnerability can corrupt heap memory used by the privileged binary, potentially allowing an attacker to execute arbitrary code with root privileges. This is a classic heap‑based buffer overflow (CWE‑122) that directly threatens confidentiality and integrity of the affected system.
Affected Systems
NTFS‑3G, any deployment that installs the SUID‑root executable of the package before the 2026.2.25 release. The upgrade path is to install any newer version where the vulnerability is patched. No vendor/product list beyond NTFS‑3G is supplied, so any host running that package is in scope.
Risk and Exploitability
Because the vulnerable binary runs with root privileges, a local attacker who can craft a malicious NTFS image can trigger the overflow, leading to privilege escalation. No EPSS score is available, but the absence of a KEV listing does not negate the potential severity. The exploitation path requires local access to mount or create files within the controlled NTFS image, meaning it is a local vulnerability. The risk is high due to the privilege level of the binary and the lack of input validation at the heap allocation site.
OpenCVE Enrichment
Debian DSA
Ubuntu USN