CVE-2026-56136

ubuntu ntfs-3g: Lesezugriff ausserhalb der Grenzen

Affected

  • ubuntu/ntfs-3g 1:2021.8.22-3ubuntu1.4..*
  • ubuntu/ntfs-3g 1:2022.10.3-1.2ubuntu3.2..*
  • ubuntu/ntfs-3g 1:2022.10.3-5ubuntu1.1..*

Description

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.

Affected operating systems

  • linux

    ubuntu / ntfs-3gjammy

  • linux

    ubuntu / ntfs-3gnoble

  • linux

    ubuntu / ntfs-3gresolute

Metrics

7.1
Source: cna-v3
1.8 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-24 21:17 UTC
CWE-125

Weakness classes (CWE)

  • CWE-125Base

    Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-08-24 21:17 UTC· cve@mitre.org
    • Affected: n/a
    • Description: In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.
    • Reference: https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r66g-c39x-cw95