Opened 5 months ago
Closed 5 months ago
#23176 closed enhancement (fixed)
ntfs-3g-2026-2.25
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New release. Fixes CVE-2026-40706.
See https://github.com/tuxera/ntfs-3g/releases/tag/2026.2.25 for changes.
Change History (4)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:3 by , 5 months ago
Description from oss-security on the issue:
Hello oss-security, A vulnerability in ntfs-3g (https://github.com/tuxera/ntfs-3g) has been reported to us by a third party. Short description: In NTFS-3G 2022.10.3, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when processing a security descriptor with multiple ACCESS_DENIED ACEs containing WRITE_OWNER from distinct group SIDs. CVSS 3.1: 7.8 (High) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References: CVE ID: CVE-2026-40706 Full advisory: https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-4cwv-5285-63v9 Fixed version: https://github.com/tuxera/ntfs-3g/releases/tag/2026.2.25
Note:
See TracTickets
for help on using tickets.

Stable Version 2026.2.25 (April 21, 2026) Changes: - Fix bashism in configure script causing errors in non-bash shells. - (mkntfs) Enable microsecond-level volume creation time. - Fix two instances of an invalid errno state when encountering NULL in strings. - Fix a crash when a reparse tag could not be found in the index. - Fix incorrect MFT free records value when bitmap is expanded. - Fix 'extras' manpages being installed when extras are disabled. - Fix various instances of use-after-free conditions in the library and tools. - Fix typo in NTFS hibernation message. Thanks to Anil Kumar for the report/fix. - Escape commas in the fsname when libfuse 2.8 or higher is used. - (ntfsclone) Allow adjusting the sector size in the NTFS boot sector for the target device when restoring images. - Remove libdl dependency when building without external plugins. - (ntfsinfo) Show information about the logfile state when dumping metadata. - (ntfsinfo) Fix displaying crowded directories or indexes. - (ntfsinfo) Fix displaying the security descriptor list in ntfsinfo. - Fix heap buffer overflow when POSIX ACLs were enabled (CVE-2026-40706). Thanks to Andrea Bocchetti for the report. - (ntfsusermap) Fix overflow when constructing backup filename. - Fix two time-of-check-time-of-use conditions. - Fix missing malloc/sscanf return value checks.Fixed at 8c80df3ce0. Leaving open for SA.