A vulnerability CVE-2022-40284 has been identified in the ntfs-3g utility from the NTFS-3G suite, which provides a user-space implementation of the NTFS file system, potentially allowing for code execution with root privileges in the system when mounting a specially crafted partition. The vulnerability has been addressed in the NTFS-3G release 2022.10.3.
The vulnerability is caused by an error in the metadata parsing code in NTFS partitions, leading to a buffer overflow when processing specially crafted NTFS filesystem images. An attack can occur when a user mounts an image or storage device prepared by an attacker, or when connecting a USB flash drive to the computer with a specially crafted partition (if the system is configured to automatically mount NTFS partitions using NTFS-3G). Working exploits for this vulnerability have not yet been demonstrated.
Source: opennet.ru
