tuxera CVE Vulnerabilities & Metrics

Focus on tuxera vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About tuxera Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tuxera. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tuxera CVEs: 32
Earliest CVE date: 13 Apr 2018, 15:29 UTC
Latest CVE date: 06 Nov 2022, 23:15 UTC

Latest CVE reference: CVE-2022-40284

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tuxera CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.05

Max CVSS: 7.2

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 29
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS tuxera CVEs

These are the five CVEs with the highest CVSS scores for tuxera, sorted by severity first and recency.

All CVEs for tuxera

CVE-2022-40284 tuxera vulnerability CVSS: 0 06 Nov 2022, 23:15 UTC

A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate attacker can exploit this if NTFS-3G software is configured to execute upon attachment of an external storage device.

CVE-2022-30789 tuxera vulnerability CVSS: 4.6 26 May 2022, 16:15 UTC

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

CVE-2022-30788 tuxera vulnerability CVSS: 4.6 26 May 2022, 16:15 UTC

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.

CVE-2022-30787 tuxera vulnerability CVSS: 4.6 26 May 2022, 16:15 UTC

An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVE-2022-30786 tuxera vulnerability CVSS: 4.6 26 May 2022, 16:15 UTC

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.

CVE-2022-30785 tuxera vulnerability CVSS: 7.2 26 May 2022, 16:15 UTC

A file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVE-2022-30784 tuxera vulnerability CVSS: 4.6 26 May 2022, 16:15 UTC

A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.

CVE-2022-30783 tuxera vulnerability CVSS: 4.6 26 May 2022, 16:15 UTC

An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.

CVE-2021-46790 tuxera vulnerability CVSS: 4.6 02 May 2022, 12:16 UTC

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

CVE-2021-39263 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.

CVE-2021-39262 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.

CVE-2021-39261 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.

CVE-2021-39260 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

CVE-2021-39259 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8.22.

CVE-2021-39258 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.

CVE-2021-39257 tuxera vulnerability CVSS: 4.7 07 Sep 2021, 15:15 UTC

A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain (starting from ntfs_attr_pwrite), causing stack consumption in NTFS-3G < 2021.8.22.

CVE-2021-39256 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.

CVE-2021-39255 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.

CVE-2021-39254 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.

CVE-2021-39253 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.

CVE-2021-39252 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

CVE-2021-39251 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

CVE-2021-35267 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.

CVE-2021-35266 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.

CVE-2021-33287 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.

CVE-2021-33286 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 15:15 UTC

In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

CVE-2021-35269 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 14:15 UTC

NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

CVE-2021-35268 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 14:15 UTC

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

CVE-2021-33289 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 14:15 UTC

In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

CVE-2021-33285 tuxera vulnerability CVSS: 6.9 07 Sep 2021, 14:15 UTC

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.

CVE-2019-9755 tuxera vulnerability CVSS: 4.4 05 Jun 2019, 15:29 UTC

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.

CVE-2017-0358 tuxera vulnerability CVSS: 7.2 13 Apr 2018, 15:29 UTC

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.