Opened 3 months ago

Closed 3 months ago

#23602 closed enhancement (fixed)

ntfs-3g-2026.7.7

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by Bruce Dubbs)

NTFS-3G 2026.7.7

Security Release 2026.7.7 (July 15, 2026)

Changes:

  • (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616)
  • Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)
  • Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618)
  • Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569)
  • Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571)
  • Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570)
  • Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572)
  • Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135)
  • Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136)

}}}

Change History (2)

comment:1 by Bruce Dubbs, 3 months ago

Description: modified (diff)
Milestone: 13.1 → 98-Security
Owner: changed from blfs-book to SecurityAdvisory

It is interesting that with all the fixes in this version, the only stat that changed was the md5sum.

Fixed at commit 99c6814a27. Leaving open for security advisory.

comment:2 by Bruce Dubbs, 3 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-150 has been issued.

Note: See TracTickets for help on using tickets.