Tuxera maintains a narrow portfolio focused on the NTFS-3G filesystem driver, a widely embedded component in Linux systems and embedded devices that provides read-write access to Windows NTFS volumes. Despite its modest disclosure volume, the driver's privileged kernel-space role and deep integration across consumer and enterprise Linux deployments gives its vulnerabilities outsized impact; a single flaw can affect millions of systems that depend on the driver for cross-platform file sharing. The recurring weakness classes—improper input validation, out-of-bounds reads and writes, buffer overflows, and integer underflow conditions—reflect the complexity of parsing untrusted filesystem structures at the kernel boundary, where memory-safety lapses can escalate to privilege escalation or system instability. Defenders should treat NTFS-3G patches as high-priority for systems that require NTFS interoperability and consider whether the driver's use case justifies the kernel-level attack surface. Current exploitation activity, severity trends, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tuxera over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0358HIGH Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A lo | Apr 13, 2018 | 7.8 | 41 | NO | YES |
CVE-2026-40706HIGH In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntf | Apr 21, 2026 | 8.4 | 29 | NO | NO |
CVE-2021-35266HIGH In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial o | Sep 7, 2021 | 7.8 | 28 | NO | NO |
CVE-2021-35269HIGH NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code | Sep 7, 2021 | 7.8 | 28 | NO | NO |
CVE-2021-35268HIGH In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution an | Sep 7, 2021 | 7.8 | 28 | NO | NO |
CVE-2021-33289HIGH In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution. | Sep 7, 2021 | 7.8 | 28 | NO | NO |
CVE-2021-46790HIGH ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by s | May 2, 2022 | 7.8 | 27 | NO | NO |
CVE-2021-35267HIGH NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when se | Sep 7, 2021 | 7.8 | 27 | NO | NO |
CVE-2021-33287HIGH In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitr | Sep 7, 2021 | 7.8 | 27 | NO | NO |
CVE-2021-33286HIGH In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution. | Sep 7, 2021 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tuxera.
Media articles that mention a CVE ID that affects a product developed by Tuxera — matched by CVE ID, not by vendor name.