Description
In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs.
INFO
Published Date :
2026-04-21T00:00:00.000Z
Last Modified :
2026-04-22T15:35:30.245Z
Source :
mitre
AFFECTED PRODUCTS
The following products are affected by CVE-2026-40706 vulnerability.
| Vendors | Products |
|---|---|
| Tuxera |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-40706.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact