CVE-2026-40706 Details
Description
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.
A heap buffer overflow vulnerability has been identified in NTFS-3G version 2022.10.3 prior to 2026.2.25. The issue arises in the function ntfs_build_permissions_posix() within acls.c. This vulnerability allows an attacker to corrupt heap memory in the SUID-root NTFS-3G binary by crafting a malicious NTFS image. The overflow occurs on the READ path (stat, readdir, open) when the software processes a security descriptor containing multiple ACCESS_DENIED ACEs with WRITE_OWNER, sourced from different group SIDs.
Users can upgrade to NTFS-3G version 2026.2.25, which addresses the heap buffer overflow vulnerability. For those using Debian 11 bullseye, the updated package version is 1:2017.3.23AR.3-4+deb11u5. Alternatively, NTFS-3G can be rebuilt without POSIX ACL support and reinstalled.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | New CVE Received | [email protected] |
| Apr 21, 2026 | CVE Modified | CVE |