Re: [BLFS Trac] #23602: ntfs-3g-2026.7.7
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23602: ntfs-3g-2026.7.7
-------------------------+-------------------------------
Reporter: Joe Locash | Owner: SecurityAdvisory
Type: enhancement | Status: new
Priority: high | Milestone: 98-Security
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+-------------------------------
Changes (by Bruce Dubbs):
* milestone: 13.1 => 98-Security
* owner: blfs-book => SecurityAdvisory
Old description:
> {{{
> NTFS-3G 2026.7.7
>
> Security Release 2026.7.7 (July 15, 2026)
>
> Changes:
> (ntfscat) Fix heap memory corruption when processing a corrupt or
> maliciously crafted filesystem. (CVE-2026-42616)
> Fix heap memory corruption when copying index data from root to an
> index block in a corrupt or maliciously crafted filesystem.
> (CVE-2026-42617)
> Fix single-byte heap buffer overflow when decompressing maliciously
> crafted compressed file data. (CVE-2026-42618)
> Fix heap buffer overflow when copying the tail data of an index block
> to a freshly allocated block. (CVE-2026-46569)
> Fix out-of-bounds read when processing symlink reparse data in a
> corrupt or maliciously crafted filesystem. (CVE-2026-46571)
> Fix heap memory corruption for maliciously crafted or corrupt index
> data descending to an out-of-bounds tree depth. (CVE-2026-46570)
> Fix heap buffer overflow for maliciously crafted or corrupt index
> data during a node split. (CVE-2026-46572)
> Fix heap buffer overflow when building inherited ACL data.
> (CVE-2026-56135)
> Fix out of bounds access when clearing an index root in maliciously
> crafted or corrupt index data. (CVE-2026-56136)
> }}}
New description:
NTFS-3G 2026.7.7
Security Release 2026.7.7 (July 15, 2026)
Changes:
- (ntfscat) Fix heap memory corruption when processing a corrupt or
maliciously crafted filesystem. (CVE-2026-42616)
- Fix heap memory corruption when copying index data from root to an index
block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)
- Fix single-byte heap buffer overflow when decompressing maliciously
crafted compressed file data. (CVE-2026-42618)
- Fix heap buffer overflow when copying the tail data of an index block to
a freshly allocated block. (CVE-2026-46569)
- Fix out-of-bounds read when processing symlink reparse data in a corrupt
or maliciously crafted filesystem. (CVE-2026-46571)
- Fix heap memory corruption for maliciously crafted or corrupt index data
descending to an out-of-bounds tree depth. (CVE-2026-46570)
- Fix heap buffer overflow for maliciously crafted or corrupt index data
during a node split. (CVE-2026-46572)
- Fix heap buffer overflow when building inherited ACL data.
(CVE-2026-56135)
- Fix out of bounds access when clearing an index root in maliciously
crafted or corrupt index data. (CVE-2026-56136)
}}}
--
Comment:
It is interesting that with all the fixes in this version, the only stat
that changed was the md5sum.
Fixed at commit 99c6814a27. Leaving open for security advisory.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23602#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page