Impact
The vulnerability is an out‑of‑bounds read in ntfs_ir_nill() in libntfs-3g/index.c of NTFS‑3G up to version 2026.2.25. A maliciously crafted file name that triggers file creation inside a mounted NTFS image lets a local user read arbitrary memory locations in the ntfs‑3g process. This results in a CWE‑125 out‑of‑bounds read, thereby exposing confidential data from the image or the host.
Affected Systems
Any deployment of NTFS‑3G older than 2026.2.26 is affected. The library is frequently bundled with Linux distributions as the default NTFS driver and is used to mount and modify NTFS images.
Risk and Exploitability
Exploitation requires local access to a machine that mounts a malicious NTFS image or allows the creation of a crafted file name on a mounted volume. The EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, meaning no publicly known exploitation yet. The CVSS score of 4.7 signals moderate severity, with a primary risk of confidentiality compromise without remote code execution. Immediate remediation, such as upgrading the driver, is advised to mitigate this risk.
OpenCVE Enrichment
Debian DSA
Ubuntu USN