Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6389-1 | ntfs-3g security update |
Ubuntu USN |
USN-8554-1 | NTFS-3G vulnerabilities |
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-122 CWE-193 |
|
| Metrics |
cvssV3_1
|
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-07T14:31:31.878Z
Reserved: 2026-04-29T00:00:00.000Z
Link: CVE-2026-42618
Updated: 2026-10-07T14:23:14.532Z
Status : Awaiting Analysis
Published: 2026-10-07T14:17:09.740
Modified: 2026-10-07T15:17:20.513
Link: CVE-2026-42618
No data.
OpenCVE Enrichment
No data.

Debian DSA
Ubuntu USN