CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-42617

unknowncovered by 2 sourcesfirst seen 2026-07-15
It was discovered that NTFS-3G had a heap buffer overflow when reading certain NTFS images. A local attacker could possibly use this issue to execute arbitrary code. (CVE-2026-42616) It was discovered that NTFS-3G had multiple heap buffer overflows when processing certain NTFS images. A local attacker could possibly use these issues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135) It was discovered that NTFS-3G had out-of-bounds reads when processing certain NTFS images. A local attacker could possibly use these issues to obtain sensitive information. (CVE-2026-46571, CVE-2026-56136)

CSIRTS triage

What
NTFS-3G has multiple vulnerabilities including heap buffer overflows and out-of-bounds reads.
Who is affected
Local attackers can exploit these vulnerabilities in NTFS-3G to execute arbitrary code or obtain sensitive information.
Urgency
The urgency is unclear, but the potential for arbitrary code execution is significant.
Action
Users should monitor for updates and apply patches as they become available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-42617

Get an email if CVE-2026-42617 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-42617

CVE.org record

Embed the live status

CVE-2026-42617 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-42617 status](https://www.csirts.com/badge/CVE-2026-42617)](https://www.csirts.com/cve/CVE-2026-42617)