Opened 5 months ago

Closed 5 months ago

#23176 closed enhancement (fixed)

ntfs-3g-2026-2.25

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New release. Fixes CVE-2026-40706.

See ​https://github.com/tuxera/ntfs-3g/releases/tag/2026.2.25 for changes.

Change History (4)

comment:1 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
Stable Version 2026.2.25 (April 21, 2026)

Changes:
    - Fix bashism in configure script causing errors in non-bash shells.
    - (mkntfs) Enable microsecond-level volume creation time.
    - Fix two instances of an invalid errno state when encountering NULL in strings.
    - Fix a crash when a reparse tag could not be found in the index.
    - Fix incorrect MFT free records value when bitmap is expanded.
    - Fix 'extras' manpages being installed when extras are disabled.
    - Fix various instances of use-after-free conditions in the library and tools.
    - Fix typo in NTFS hibernation message. Thanks to Anil Kumar for the report/fix.
    - Escape commas in the fsname when libfuse 2.8 or higher is used.
    - (ntfsclone) Allow adjusting the sector size in the NTFS boot sector for the target device when restoring images.
    - Remove libdl dependency when building without external plugins.
    - (ntfsinfo) Show information about the logfile state when dumping metadata.
    - (ntfsinfo) Fix displaying crowded directories or indexes.
    - (ntfsinfo) Fix displaying the security descriptor list in ntfsinfo.
    - Fix heap buffer overflow when POSIX ACLs were enabled (CVE-2026-40706). Thanks to Andrea Bocchetti for the report.
    - (ntfsusermap) Fix overflow when constructing backup filename.
    - Fix two time-of-check-time-of-use conditions.
    - Fix missing malloc/sscanf return value checks.

Fixed at 8c80df3ce0. Leaving open for SA.

comment:3 by Douglas R. Reno, 5 months ago

Description from oss-security on the issue:

Hello oss-security,

A vulnerability in ntfs-3g (https://github.com/tuxera/ntfs-3g) has been reported to us 
by a third party.

Short description:

In NTFS-3G 2022.10.3, a heap buffer overflow exists in ntfs_build_permissions_posix() in 
acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by 
crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, 
readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs 
containing WRITE_OWNER from distinct group SIDs.

CVSS 3.1: 7.8 (High) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References:
CVE ID: CVE-2026-40706
Full advisory: https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-4cwv-5285-63v9
Fixed version: https://github.com/tuxera/ntfs-3g/releases/tag/2026.2.25

comment:4 by Douglas R. Reno, 5 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-054 issued.

Note: See TracTickets for help on using tickets.