Opened 3 months ago
Closed 3 months ago
#23602 closed enhancement (fixed)
ntfs-3g-2026.7.7
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description (last modified by )
NTFS-3G 2026.7.7
Security Release 2026.7.7 (July 15, 2026)
Changes:
- (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616)
- Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)
- Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618)
- Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569)
- Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571)
- Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570)
- Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572)
- Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135)
- Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136)
}}}
Change History (2)
comment:1 by , 3 months ago
| Description: | modified (diff) |
|---|---|
| Milestone: | 13.1 → 98-Security |
| Owner: | changed from to |
comment:2 by , 3 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-150 has been issued.
Note:
See TracTickets
for help on using tickets.

It is interesting that with all the fixes in this version, the only stat that changed was the md5sum.
Fixed at commit 99c6814a27. Leaving open for security advisory.