Back

HIGH

ntfs-3g: Modprobe influence vulnerability via environment variables

Published Apr 13, 2018

Description

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Apr 13, 2018
Updated Dec 4, 2025
Reserved Nov 29, 2016
CISA Vulnrichment
Updated Dec 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a