{"id":"CVE-2021-33289","title":"In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.","summary":"In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"tuxera","product":"ntfs-3g","affected":["ntfs-3g < 2021.8.22","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0","fedora = 33","fedora = 35"],"patched":["ntfs-3g 2021.8.22"],"published":"2021-09-07","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-33289","references":[{"url":"http://www.openwall.com/lists/oss-security/2021/08/30/1","label":"cve@mitre.org"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-q759-8j5v-q5jp","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/11/msg00013.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/766ISTT3KCARKFUIQT7N6WV6T63XOKG3/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HSEKTKHO5HFZHWZNJNBJZA56472KRUZI/","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202301-01","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2021/dsa-4971","label":"cve@mitre.org"},{"url":"http://ntfs-3g.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2021/08/30/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-q759-8j5v-q5jp","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/11/msg00013.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/766ISTT3KCARKFUIQT7N6WV6T63XOKG3/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSEKTKHO5HFZHWZNJNBJZA56472KRUZI/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202301-01","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4971","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00488,"epssPercentile":0.41073,"ingestedAt":"2026-07-06T01:08:16.802Z","slug":"CVE-2021-33289","body":"## Overview\n\nIn NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.\n\n## Affected\n\n- `ntfs-3g < 2021.8.22`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `fedora = 33`\n- `fedora = 35`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ntfs-3g 2021.8.22`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}