Tuxera released NTFS-3G 2026.9.18 to remediate eight vulnerabilities in the FUSE-based NTFS filesystem driver. The flaws include heap buffer overflows, heap data corruption, out-of-bounds reads and writes, and a denial-of-service condition in code handling NTFS attributes, mapping-pair decompression, extended attributes, restart areas, security identifiers, ACL ownership, and inode extent attachment. The highest reported severity is CVSS 6.8 (Moderate), affecting a heap buffer overflow in ntfs_same_sid().
Tuxera also issued patch bundles for the 2022.10.3 and 2026.7.7 branches, while Fedora shipped advisory FEDORA-2026-a2beb6a664 for affected Fedora 46 packages, including ntfs-3g, ntfs-3g-system-compression, partclone, testdisk, and wimlib. The update additionally corrects ACL-inheritance behavior and defects in ntfscat and ntfsresize; CVE identifiers had been requested but were not assigned at disclosure, and no known exploits were reported.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Fedora published advisory FEDORA-2026-a2beb6a664 for Fedora 46, covering ntfs-3g, ntfs-3g-system-compression, partclone, testdisk, and wimlib. The available advisory metadata did not specify a CVE, severity, technical impact, or remediation version.
Alongside the vulnerability disclosure, Tuxera released patch bundles for the ntfs-3g 2022.10.3 and 2026.7.7 release branches.
Tuxera disclosed eight NTFS-3G flaws—including heap buffer overflows, heap data corruption, an out-of-bounds read/write issue, and a denial-of-service condition—and released ntfs-3g 2026.9.18 to fix them. The highest reported severity was CVSS 6.8 for the ntfs_same_sid() heap buffer overflow; CVE IDs had been requested but were still pending.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceseclists.org
Open sourcephoronix.com
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.