Re: [BLFS Trac] #23176: ntfs-3g-2026-2.25

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23176: ntfs-3g-2026-2.25
-------------------------+-------------------------------
 Reporter:  Joe Locash   |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Comment (by Douglas R. Reno):

 Description from oss-security on the issue:

 {{{
 Hello oss-security,

 A vulnerability in ntfs-3g (https://github.com/tuxera/ntfs-3g) has been
 reported to us
 by a third party.

 Short description:

 In NTFS-3G 2022.10.3, a heap buffer overflow exists in
 ntfs_build_permissions_posix() in
 acls.c that allows an attacker to corrupt heap memory in the SUID-root
 ntfs-3g binary by
 crafting a malicious NTFS image. The overflow is triggered on the READ
 path (stat,
 readdir, open) when processing a security descriptor with multiple
 ACCESS_DENIED ACEs
 containing WRITE_OWNER from distinct group SIDs.

 CVSS 3.1: 7.8 (High) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

 References:
 CVE ID: CVE-2026-40706
 Full advisory: https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-
 4cwv-5285-63v9
 Fixed version: https://github.com/tuxera/ntfs-3g/releases/tag/2026.2.25
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23176#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.