In NTFS-3G through 2026.2.25, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by extending a directory, e.g., by creating a file.
1:2016.2.22AR.2-21:2017.3.23-21:2017.3.23-2ubuntu0.18.04.11:2017.3.23-2ubuntu0.18.04.21:2017.3.23-2ubuntu0.18.04.31:2017.3.23-2ubuntu0.18.04.41:2017.3.23-2ubuntu0.18.04.51:2017.3.23AR.3-3ubuntu11:2017.3.23AR.3-3ubuntu1.11:2017.3.23AR.3-3ubuntu1.21:2017.3.23AR.3-3ubuntu1.31:2021.8.22-3ubuntu1.41:2022.10.3-1.2ubuntu3.21:2022.10.3-5ubuntu1.11:2014.2.15AR.3-31:2015.3.14AR.1-11:2015.3.14AR.1-1build11:2015.3.14AR.1-1ubuntu0.11:2015.3.14AR.1-1ubuntu0.21:2015.3.14AR.1-1ubuntu0.31:2015.3.14AR.1-1ubuntu0.3+esm11:2015.3.14AR.1-1ubuntu0.3+esm21:2015.3.14AR.1-1ubuntu0.3+esm31:2015.3.14AR.1-1ubuntu0.3+esm4