CVE-2026-56136: Medium severity debian/ntfs-3g vulnerability
In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfsirnill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntfs-3gto a version that resolves this vulnerability.Fixed in 1:2022.10.3-5+deb13u2Fixed in 1:2026.7.7-2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56136?
CVE-2026-56136 has a risk rating of 30, indicating a significant security vulnerability.
How do I fix CVE-2026-56136?
To remediate CVE-2026-56136, update to the latest version of the ntfs-3g package available for your Debian system.
What impact does CVE-2026-56136 have on affected systems?
CVE-2026-56136 can lead to data corruption and potential unauthorized access to sensitive information.
Which versions of ntfs-3g are affected by CVE-2026-56136?
CVE-2026-56136 affects specific versions of the ntfs-3g package in Debian prior to the fix release.
When was CVE-2026-56136 last updated?
CVE-2026-56136 was last updated on 16 July 2026.