
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-46572 is a heap buffer overflow vulnerability in ntfs-3g, the read/write NTFS driver for FUSE, triggered when building inherited ACL (Access Control List) data from maliciously crafted or corrupt NTFS filesystem structures. It is one of several heap buffer overflow issues disclosed together affecting ntfs-3g. The CVE status is currently listed as "Reserved" with limited published details. Affected distributions include Debian Linux and Ubuntu (22.04 LTS, 24.04 LTS, and 26.04 LTS). The vulnerability is estimated to be of MEDIUM severity by Feedly's CVSS category estimate (Ubuntu Advisory, Feedly).
The root cause is a heap buffer overflow (CWE-122) in ntfs-3g's ACL inheritance logic, which fails to properly validate or bound-check data when processing inherited ACL entries from specially crafted or corrupt NTFS filesystem images. An attacker can trigger this flaw by supplying a malicious NTFS image to a system that mounts it using ntfs-3g. Exploitation requires local access or the ability to influence which NTFS image is mounted. The vulnerability was initially disclosed via the oss-security mailing list and subsequently tracked by Debian and Ubuntu security teams (Ubuntu Advisory, OSS-Sec).
Successful exploitation of CVE-2026-46572 could allow a local attacker to execute arbitrary code in the context of the ntfs-3g process, which may run with elevated privileges depending on system configuration. This poses a risk to confidentiality, integrity, and availability of the affected system. The vulnerability is grouped with related ntfs-3g heap buffer overflows (CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-56135) that share the same potential for arbitrary code execution (Ubuntu Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-46572 at this time. The CVE remains in "Reserved" status, and exploitation requires local access to supply or influence a malicious NTFS image. No EPSS score or CISA KEV catalog entry has been identified for this CVE. Detection plugins have been published by Tenable Nessus (plugin IDs 327130, 327201, 327650, 329286) for affected Debian and Ubuntu systems (Tenable, Feedly).
Ubuntu has released patched package versions addressing CVE-2026-46572 and related ntfs-3g vulnerabilities: Ubuntu 26.04 LTS: ntfs-3g / libntfs-3g89t64 version 1:2022.10.3-5ubuntu1.1; Ubuntu 24.04 LTS: version 1:2022.10.3-1.2ubuntu3.2; Ubuntu 22.04 LTS: version 1:2021.8.22-3ubuntu1.4. SUSE has also issued a security update (SUSE-SU-2026:3213-1 / 3214-1). Administrators should apply standard system updates to pull in the fixed packages. No specific configuration-based workaround has been published; the recommended action is to update to the patched versions promptly (Ubuntu Advisory, SUSE Advisory).
The vulnerability was disclosed via the oss-security mailing list and subsequently covered by Linux security news outlets including LinuxSecurity.com and LinuxCompatible.org. The Solus Linux community also noted the fix in their weekly update digest. No notable individual researcher commentary or significant social media discussion has been identified beyond routine patch tracking (OSS-Sec, LinuxSecurity).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."