Impact
A heap‑based buffer overflow exists in the build_inherited_id() function inside the security module of NTFS‑3G. The flaw is triggered when the SUID‑root binary processes a malicious NTFS image that contains a specially crafted directory and file, causing the function to overflow a buffer and corrupt heap memory. Because the binary runs with root privileges, an attacker who can trigger this overflow may be able to execute arbitrary code as root, compromising confidentiality, integrity, and availability of the host system.
Affected Systems
Any installation of NTFS‑3G that includes the SUID‑root ntfs‑3g executable and is at or before version 2026.2.25. Hosts running this package without the patched binary are susceptible; upgrading to a later released version that contains the patch removes the flaw.
Risk and Exploitability
The vulnerable binary runs with root privileges, so a local attacker who can craft a malicious NTFS image can trigger the overflow and achieve privilege escalation. The CVSS score of 7.4 indicates high severity. The EPSS score of less than 1 % indicates a low yet non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires local access to mount or create files inside the crafted NTFS image and therefore is a local vulnerability; however, once triggered it can lead to complete compromise of the system.
OpenCVE Enrichment
Debian DSA
Ubuntu USN