CVE-2026-56135: Buffer Overflow
In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function buildinheritedid() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by creating a file in a crafted directory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntfs-3gto a version that resolves this vulnerability.Fixed in 1:2022.10.3-5+deb13u2Fixed in 1:2026.7.7-2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56135?
CVE-2026-56135 has a risk rating of 30.
How do I fix CVE-2026-56135?
To fix CVE-2026-56135, update your ntfs-3g package to the latest version available.
What software is affected by CVE-2026-56135?
CVE-2026-56135 affects the ntfs-3g software on Debian systems.
What types of systems are vulnerable to CVE-2026-56135?
Any Debian system using the ntfs-3g package is vulnerable to CVE-2026-56135.
When was CVE-2026-56135 last updated?
CVE-2026-56135 was last updated on 16 July 2026.