OVERVIEW CVE-2026-40706 is a heap buffer overflow vulnerability in NTFS-3G versions before 2026.2.25 (specifically affecting 2022.10.3 and later) located in the ntfs_build_permissions_posix() function within acls.c. The vulnerability can be exploited by crafting a malicious NTFS filesystem image that triggers memory corruption in the SUID-root ntfs-3g binary when performing basic file operations such as stat, readdir, or open commands. SEVERITY This vulnerability carries a CVSS v3.1 score of 8.4 (HIGH) with a local attack vector requiring no privileges and minimal user interaction. The attack has high impact across confidentiality, integrity, and availability, as successful exploitation of the SUID-root binary could enable privilege escalation and complete system compromise. The overflow is triggered during normal read path operations when the filesystem contains specially crafted security descriptors with multiple ACCESS_DENIED ACEs. EXPLOITATION STATUS There is currently no indication of active exploitation in the wild, as the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and maintains an inactive status on threat intelligence hot lists. The EPSS score of 0.00013 indicates minimal current exploit probability. However, the relatively moderate FAUCET risk score of 50.0/100 warrants prompt patching, as proof-of-concept exploitation is theoretically straightforward given the local nature of the attack.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2022.10.3, < 2026.2.25CPE match | cpe:2.3:a:tuxera:ntfs-3g:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.