﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
24005	ntfs-3g-2026.9.18	Joe Locash	SecurityAdvisory	"**Security Release 2026.9.18 (September 23, 2026)**

Changes:
    - Guard against multiple creator-owner and creator-group ACEs during ACL inheritance.
    - (ntfscat) Fix missing cleanup of opened attribute on error (issue !#212).
    - Fix heap out of bounds read/write in ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv, CVE pending)
    - Fix heap data corruption in ntfs_mapping_pairs_decompress_i(). (GHSA-mc3c-983p-wqm8, CVE pending)
    - Fix heap buffer overflow in ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3, CVE pending)
    - Fix heap buffer overflow in ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8, CVE pending)
    - Fix heap buffer overflow in ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x, CVE pending)
    - Fix denial-of-service in ntfs_inode_attach_all_extents(). (GHSA-jcjj-9262-6j6p, CVE pending)
    - Fix heap buffer overflow in ntfs_same_sid(). (GHSA-x98j-3g35-f59x, CVE pending)
    - Fix heap buffer overflow in ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72, CVE pending)
    - (ntfsresize) Fix stale $MFTMirr data when the first extent of $MFT is relocated (issue !#209)."	enhancement	closed	elevated	98-Security	BOOK	git	medium	fixed		
