[ GLSA 202608-13 ] NTFS-3G: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178684919883.1.5873753282469433391@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-13
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: NTFS-3G: Multiple Vulnerabilities
     Date: August 16, 2026
     Bugs: #973067, #979306
       ID: 202608-13

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in NTFS-3G, the worst of which
could result in privilege escalation.

Background
==========

NTFS-3G is a stable, full-featured, read-write NTFS driver for various
operating systems.

Affected packages
=================

Package        Vulnerable    Unaffected
-------------  ------------  ------------
sys-fs/ntfs3g  < 2026.7.7    >= 2026.7.7

Description
===========

Multiple vulnerabilities have been discovered in NTFS-3G. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All NTFS-3G users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=sys-fs/ntfs3g-2026.7.7"

References
==========

[ 1 ] CVE-2026-40706
      https://nvd.nist.gov/vuln/detail/CVE-2026-40706
[ 2 ] CVE-2026-42616
      https://nvd.nist.gov/vuln/detail/CVE-2026-42616
[ 3 ] CVE-2026-42617
      https://nvd.nist.gov/vuln/detail/CVE-2026-42617
[ 4 ] CVE-2026-42618
      https://nvd.nist.gov/vuln/detail/CVE-2026-42618
[ 5 ] CVE-2026-46569
      https://nvd.nist.gov/vuln/detail/CVE-2026-46569
[ 6 ] CVE-2026-46570
      https://nvd.nist.gov/vuln/detail/CVE-2026-46570
[ 7 ] CVE-2026-46571
      https://nvd.nist.gov/vuln/detail/CVE-2026-46571
[ 8 ] CVE-2026-46572
      https://nvd.nist.gov/vuln/detail/CVE-2026-46572
[ 9 ] CVE-2026-56135
      https://nvd.nist.gov/vuln/detail/CVE-2026-56135
[ 10 ] CVE-2026-56136
      https://nvd.nist.gov/vuln/detail/CVE-2026-56136

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-13

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqBJ64bFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZzMsP/RGpwhkdwDkkEiFSr2nK
uY2QM1A7fAUJXssAgcOhg85fj7+QfCS0nQ/Ev5ngOkemKI4Sp2uBj/4VBxtD+bdo
0hHMGeUUu0V02RBSmuvXUIxSV1ufxLv9ycOzdBFEf9Vr4LMSjQtLH7NTCN+UwN0W
1KUDp5oyg9FsuyJnE6/AinY/5PHefRpUeoLNbIqruv+YguaKRwP+AmQ/q1los7Q4
tEk4oLMzQZVz8sLqZdGMELsXNbiL/TKe/hmATkXsNeXyN0WMyhWJLYWT4HG0nBdQ
KdCJy7XCyejw8iElVQ5FecBBHddPLRvRJWCYcOBPeI+ZnCnkH4jo0iEivv4imqfy
4mDfCqa3s520TaRjwTVK3dFxYSaRL+y/k2p+zTHIAMieIUMQ/FDwZbU6kYOCZbM6
U5nPsrtQvF4HC0BzLi8gwRSIn1C5DR9TQsB2INsySQuiVf59PvfDexyrLPOAJL4f
cW6o2ZbPzy13T9nWSnywJ3yLOWm/7kTs6j2BByGLTzO/Wc1HKM1StYfWUyORLnea
SX3DV5ea6gzB0j1cZHqY5v5x2ff4L3zobmNnjq1F2BZwfDBMFA1EJZj3rdIz+zFs
+5MgWxbMxNgXE00xA9TaLJ5wEMbH8I2Hg3axqrBsgwnHRDuWLFEd3EuNxr5Uq1i9
bER9OshGWTzzPxH9e+uB1Nrc
=t9Kp
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.