Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-42618

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 NTFS-3G 2026.7.7 之前的版本中,compress.c 文件里的 ntfs_decompress() 函数存在一个堆缓冲区溢出漏洞。攻击者通过构造恶意的 NTFS 镜像文件,可以破坏 SUID-root 权限的 ntfs-3g 二进制文件中的一个字节的堆内存。该漏洞可以通过读取精心构造的文件触发。

AI Predicted 7.8 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-42618

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered by reading the special crafted file.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-42618

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-42618

请登录查看更多情报信息。

Other References for CVE-2026-42618 (2)

Same Patch Batch · n/a · 2026-10-07 · 15 CVEs total

CVE-2026-88514 iTerm2 macOS 低于 3.6.12 本地敏感信息泄露漏洞
CVE-2026-46572 ntfs-3G堆缓冲区溢出漏洞
CVE-2026-42616 NTFS-3G heap缓冲区溢出漏洞
CVE-2026-42617 ntfs-3g堆缓冲区溢出漏洞
CVE-2026-46569 ntfs-3G低于2026.7.7的堆缓冲区溢出漏洞
CVE-2026-46571 NTFS-3G 越界读漏洞,影响 2026.7.7 前版本
CVE-2026-46570 NTFS-3G <2026.7.7堆溢出漏洞
CVE-2025-70516 Fonvil X7A v2.6.0.1182 Websocket认证绕过漏洞
CVE-2025-70515 Fanvil x7a 2.6.0.1182存储型XSS漏洞
CVE-2025-70517 Fanvil x7a 2.6.0.1182 CSRF漏洞
CVE-2025-70520 Fanvil x7a 2.6.0.1182 认证绕过漏洞
CVE-2025-70519 Fanvil x7a v2.6.0.1182存在存储型XSS漏洞
CVE-2025-70521 Fanvil x7a v2.6.0.1182诊断Ping命令注入漏洞
CVE-2025-70518 Fintel x7a固件2.6.0.1182远程命令执行漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-42618

No comments yet


Leave a comment