CVE-2026-46572
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-46572 is a heap buffer overflow vulnerability in ntfs-3g, the read/write NTFS driver for FUSE, triggered when building inherited ACL (Access Control List) data from maliciously crafted or corrupt NTFS filesystem structures. It is one of several heap buffer overflow issues disclosed together affecting ntfs-3g. The CVE status is currently listed as "Reserved" with limited published details. Affected distributions include Debian Linux and Ubuntu (22.04 LTS, 24.04 LTS, and 26.04 LTS). The vulnerability is estimated to be of MEDIUM severity by Feedly's CVSS category estimate (Ubuntu Advisory, Feedly).

Technical details

The root cause is a heap buffer overflow (CWE-122) in ntfs-3g's ACL inheritance logic, which fails to properly validate or bound-check data when processing inherited ACL entries from specially crafted or corrupt NTFS filesystem images. An attacker can trigger this flaw by supplying a malicious NTFS image to a system that mounts it using ntfs-3g. Exploitation requires local access or the ability to influence which NTFS image is mounted. The vulnerability was initially disclosed via the oss-security mailing list and subsequently tracked by Debian and Ubuntu security teams (Ubuntu Advisory, OSS-Sec).

Impact

Successful exploitation of CVE-2026-46572 could allow a local attacker to execute arbitrary code in the context of the ntfs-3g process, which may run with elevated privileges depending on system configuration. This poses a risk to confidentiality, integrity, and availability of the affected system. The vulnerability is grouped with related ntfs-3g heap buffer overflows (CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-56135) that share the same potential for arbitrary code execution (Ubuntu Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-46572 at this time. The CVE remains in "Reserved" status, and exploitation requires local access to supply or influence a malicious NTFS image. No EPSS score or CISA KEV catalog entry has been identified for this CVE. Detection plugins have been published by Tenable Nessus (plugin IDs 327130, 327201, 327650, 329286) for affected Debian and Ubuntu systems (Tenable, Feedly).

Mitigation and workarounds

Ubuntu has released patched package versions addressing CVE-2026-46572 and related ntfs-3g vulnerabilities: Ubuntu 26.04 LTS: ntfs-3g / libntfs-3g89t64 version 1:2022.10.3-5ubuntu1.1; Ubuntu 24.04 LTS: version 1:2022.10.3-1.2ubuntu3.2; Ubuntu 22.04 LTS: version 1:2021.8.22-3ubuntu1.4. SUSE has also issued a security update (SUSE-SU-2026:3213-1 / 3214-1). Administrators should apply standard system updates to pull in the fixed packages. No specific configuration-based workaround has been published; the recommended action is to update to the patched versions promptly (Ubuntu Advisory, SUSE Advisory).

Community reactions

The vulnerability was disclosed via the oss-security mailing list and subsequently covered by Linux security news outlets including LinuxSecurity.com and LinuxCompatible.org. The Solus Linux community also noted the fix in their weekly update digest. No notable individual researcher commentary or significant social media discussion has been identified beyond routine patch tracking (OSS-Sec, LinuxSecurity).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63343CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-63125CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-62941CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-62940CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026
CVE-2026-62867CRITICAL9.9
  • Linux Debian logoLinux Debian
  • incus
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management