
CVE-2026-40706: ntfs-3g 2022.10.3: Heap buffer overflow https://www.openwall.com/lists/oss-security/2026/04/21/4 allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open).
Post summary
A new heap buffer overflow vulnerability (CVE‑2026‑40706) in ntfs‑3g 2022.10.3 has been disclosed, allowing attackers to corrupt heap memory with malicious NTFS images.


