Multiple heap buffer overflows and out-of-bounds read vulnerabilities in NTFS-3G (CVE-2026-42616 through CVE-2026-56136) allow a local attacker to potentially execute arbitrary code or obtain sensitive information by processing a specially crafted NTFS filesystem image. The article does not provide specific affected version ranges, CVSS scores, fixed version numbers, or workaround information.
It was discovered that NTFS-3G had a heap buffer overflow when reading certain NTFS images. A local attacker could possibly use this issue to execute arbitrary code. (CVE-2026-42616) It was discovered that NTFS-3G had multiple heap buffer overflows when processing certain NTFS images. A local attacker could possibly use these issues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135) It was discovered that NTFS-3G had out-of-bounds reads when processing certain NTFS images. A local attacker could possibly use these issues to obtain sensitive information. (CVE-2026-46571, CVE-2026-56136)