
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46571 is an out-of-bounds read vulnerability in ntfs-3g that occurs when processing symlink reparse data from a corrupt or maliciously crafted NTFS filesystem image. The vulnerability affects the ntfs-3g package across multiple Linux distributions, including Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. It was disclosed in July 2026 and carries an estimated CVSS severity of Medium (Ubuntu Advisory, Feedly). The CVE status is currently listed as Reserved.
The root cause is an out-of-bounds read (CWE-125) in ntfs-3g's handling of symlink reparse data when parsing NTFS filesystem images. An attacker can trigger this flaw by supplying a specially crafted or corrupt NTFS image containing malformed symlink reparse point data, causing the driver to read beyond the bounds of an allocated buffer. Exploitation requires that the attacker can cause the vulnerable system to mount or process a crafted NTFS image, which typically implies local access or control over the filesystem being mounted (Ubuntu Advisory, OSV).
Successful exploitation of CVE-2026-46571 allows a local attacker to read out-of-bounds memory, potentially exposing sensitive information from the system's memory space. The primary impact is a confidentiality breach; integrity and availability are not directly affected by this out-of-bounds read. The vulnerability is part of a broader set of ntfs-3g flaws disclosed simultaneously, some of which (CVE-2026-42616 through CVE-2026-56135) allow arbitrary code execution via heap buffer overflows, increasing the overall risk profile of the affected package (Ubuntu Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-46571 as of the available data. The vulnerability requires local access to supply a crafted NTFS image, limiting its remote exploitability. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Tenable Nessus (plugin IDs 327173, 329286, 329281) (Tenable, Feedly).
Ubuntu has released patched package versions addressing CVE-2026-46571 and related ntfs-3g vulnerabilities. Users should update to the following versions or later:
ntfs-3g / libntfs-3g89t64 ≥ 1:2022.10.3-5ubuntu1.1ntfs-3g / libntfs-3g89t64 ≥ 1:2022.10.3-1.2ubuntu3.2ntfs-3g / libntfs-3g89 ≥ 1:2021.8.22-3ubuntu1.4SUSE has also issued a security update (SUSE-SU-2026:3213-1) and Debian patches are available. A standard system update (apt upgrade) is sufficient to apply the fix on Ubuntu systems (Ubuntu Advisory, SUSE Advisory).
The vulnerability was disclosed via the oss-security mailing list in July 2026 alongside several related ntfs-3g flaws. Linux distribution vendors including Ubuntu, Debian, and SUSE responded promptly with security advisories and patched packages within days of disclosure. Community coverage was noted on Linux-focused news aggregators and security advisory trackers (oss-security, Ubuntu Advisory, SUSE Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."