Opened 28 hours ago

Last modified 27 hours ago

#24005 new enhancement

ntfs-3g-2026.9.18

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Security Release 2026.9.18 (September 23, 2026)

Changes:

  • Guard against multiple creator-owner and creator-group ACEs during ACL inheritance.
  • (ntfscat) Fix missing cleanup of opened attribute on error (issue #212).
  • Fix heap out of bounds read/write in ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv, CVE pending)
  • Fix heap data corruption in ntfs_mapping_pairs_decompress_i(). (GHSA-mc3c-983p-wqm8, CVE pending)
  • Fix heap buffer overflow in ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3, CVE pending)
  • Fix heap buffer overflow in ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8, CVE pending)
  • Fix heap buffer overflow in ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x, CVE pending)
  • Fix denial-of-service in ntfs_inode_attach_all_extents(). (GHSA-jcjj-9262-6j6p, CVE pending)
  • Fix heap buffer overflow in ntfs_same_sid(). (GHSA-x98j-3g35-f59x, CVE pending)
  • Fix heap buffer overflow in ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72, CVE pending)
  • (ntfsresize) Fix stale $MFTMirr data when the first extent of $MFT is relocated (issue #209).

Change History (1)

comment:1 by Joe Locash, 27 hours ago

Milestone: 13.2 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 97387a79de. Leaving open for SA.

Note: See TracTickets for help on using tickets.