Vulnerabilities in ntfs-3g
Tuxera fixed multiple moderate heap buffer overflows in ntfs-3g with version 2026.9.18.
Rostislav disclosed multiple vulnerabilities in Tuxera’s ntfs-3g driver, fixed in version 2026.9.18. Reported issues include a heap buffer overflow in ntfs_acl_owner(), scored CVSS 6.2 and rated moderate, and a heap buffer overflow in ntfs_same_sid(), scored CVSS 6.8. Jurre van Bergen is credited for the first issue. The oss-security post does not say the flaws are being exploited.
- Fixes shipped in ntfs-3g 2026.9.18
- Heap overflow in ntfs_acl_owner() scored CVSS 6.2
- Heap overflow in ntfs_same_sid() scored CVSS 6.8
- Post does not report active exploitation
Posted by Rostislav on Sep 23 Hello oss-security, https://github.com/tuxera/ntfs-3g). The vulnerabilities have been fixed in version 2026.9.18. Below is the list of vulnerabilities with their CVSS score and severity: [NTFS-3G-SA_2026-06-1_20] Heap buffer overflow in ntfs_acl_owner() CVSS: 6.2 Severity: Moderate Credit: Jurre van Bergen [NTFS-3G-SA_2026-06-1_19] Heap buffer overflow in ntfs_same_sid() CVSS: 6.8...
This source does not provide full text. Read it at seclists.org.