CVE-2026-56136
ubuntu ntfs-3g: Lesezugriff ausserhalb der Grenzen
highEPSS 0.1%
Affected
- ubuntu/ntfs-3g
1:2021.8.22-3ubuntu1.4..* - ubuntu/ntfs-3g
1:2022.10.3-1.2ubuntu3.2..* - ubuntu/ntfs-3g
1:2022.10.3-5ubuntu1.1..*
Description
In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.
Affected operating systems
linux
ubuntu / ntfs-3gjammy
linux
ubuntu / ntfs-3gnoble
linux
ubuntu / ntfs-3gresolute
Metrics
Show all metrics
Severity
high
62.36
no public PoC known
7.1
Published
2026-08-24 21:17 UTC
CWE-125
Weakness classes (CWE)
CWE-125Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-08-24 21:17 UTC· cve@mitre.org
- Affected: n/a
- Description: In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.
- Reference: https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r66g-c39x-cw95