DSA-6389-1 ntfs-3g - security update
Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation. https://security-tracker.debian.org/tracker/DSA-6389-1
CSIRTS triage
- What
- Several vulnerabilities in NTFS-3G allow local users to escalate privileges.
- Who is affected
- Local users of NTFS-3G are affected.
- Urgency
- Remediation is urgent as these vulnerabilities can lead to local root privilege escalation, though exploitation is not confirmed.
- Action
- Update NTFS-3G to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ntfs-3g
Get an email when a new ntfs-3g advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00300.html
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-42616 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42617 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42618 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46569 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46570 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46571 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46572 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56135 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56136 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8554-1: NTFS-3G vulnerabilitiesubuntu
More from Debian Security Advisories
- unknownDSA-6409-1 libgd2 - security update2026-08-01
- unknownDSA-6408-1 chromium - security update2026-07-31
- unknownDSA-6405-1 linux - security update2026-07-31
- unknownDSA-6406-1 php8.4 - security update2026-07-31
- unknownDSA-6407-1 incus - security update2026-07-31