Re: [BLFS Trac] #23602: ntfs-3g-2026.7.7

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23602: ntfs-3g-2026.7.7
-------------------------+-------------------------------
 Reporter:  Joe Locash   |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  98-Security
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Changes (by Bruce Dubbs):

 * milestone:  13.1 => 98-Security
 * owner:  blfs-book => SecurityAdvisory


Old description:

> {{{
> NTFS-3G 2026.7.7
>
> Security Release 2026.7.7 (July 15, 2026)
>
> Changes:
>     (ntfscat) Fix heap memory corruption when processing a corrupt or
> maliciously crafted filesystem. (CVE-2026-42616)
>     Fix heap memory corruption when copying index data from root to an
> index block in a corrupt or maliciously crafted filesystem.
> (CVE-2026-42617)
>     Fix single-byte heap buffer overflow when decompressing maliciously
> crafted compressed file data. (CVE-2026-42618)
>     Fix heap buffer overflow when copying the tail data of an index block
> to a freshly allocated block. (CVE-2026-46569)
>     Fix out-of-bounds read when processing symlink reparse data in a
> corrupt or maliciously crafted filesystem. (CVE-2026-46571)
>     Fix heap memory corruption for maliciously crafted or corrupt index
> data descending to an out-of-bounds tree depth. (CVE-2026-46570)
>     Fix heap buffer overflow for maliciously crafted or corrupt index
> data during a node split. (CVE-2026-46572)
>     Fix heap buffer overflow when building inherited ACL data.
> (CVE-2026-56135)
>     Fix out of bounds access when clearing an index root in maliciously
> crafted or corrupt index data. (CVE-2026-56136)
> }}}

New description:

 NTFS-3G 2026.7.7

 Security Release 2026.7.7 (July 15, 2026)

 Changes:
 - (ntfscat) Fix heap memory corruption when processing a corrupt or
 maliciously crafted filesystem. (CVE-2026-42616)
 - Fix heap memory corruption when copying index data from root to an index
 block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)
 - Fix single-byte heap buffer overflow when decompressing maliciously
 crafted compressed file data. (CVE-2026-42618)
 - Fix heap buffer overflow when copying the tail data of an index block to
 a freshly allocated block. (CVE-2026-46569)
 - Fix out-of-bounds read when processing symlink reparse data in a corrupt
 or maliciously crafted filesystem. (CVE-2026-46571)
 - Fix heap memory corruption for maliciously crafted or corrupt index data
 descending to an out-of-bounds tree depth. (CVE-2026-46570)
 - Fix heap buffer overflow for maliciously crafted or corrupt index data
 during a node split. (CVE-2026-46572)
 - Fix heap buffer overflow when building inherited ACL data.
 (CVE-2026-56135)
 - Fix out of bounds access when clearing an index root in maliciously
 crafted or corrupt index data. (CVE-2026-56136)
 }}}

--
Comment:

 It is interesting that with all the fixes in this version, the only stat
 that changed was the md5sum.

 Fixed at commit 99c6814a27.  Leaving open for security advisory.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23602#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.