cve-2026-56136

MEDIUM CVSS 4.7 nvd
Description

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.

Timeline
Published
2026-08-24
Last Modified
2026-09-09
CVSS Details
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 4.7 MEDIUM CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N 1.0 3.6 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD metadata
NVD status
Awaiting Analysis
Source identifier
cve@mitre.org
References
Linked Vulnerabilities

{
  "cvss": 4.7,
  "datePublished": "2026-08-24T21:17:42.380",
  "dateUpdated": "2026-09-09T16:03:22.897",
  "description": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name.",
  "id": "CVE-2026-56136",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered by creation of a file with a crafted name."
      }
    ],
    "id": "CVE-2026-56136",
    "lastModified": "2026-09-09T16:03:22.897",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.0,
          "impactScore": 3.6,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-56136",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-28T16:20:05.998614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-08-24T21:17:42.380",
    "references": [
      {
        "source": "cve@mitre.org",
        "url": "https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r66g-c39x-cw95"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  },
  "severity": "MEDIUM",
  "source": "nvd",
  "title": "In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an att..."
}
View JSON API Download JSON