Updated ntfs-3g packages fix security vulnerabilities
Publication date: 20 Sep 2026Modification date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136
Description
Heap memory corruption when processing a corrupt or maliciously crafted
filesystem. (CVE-2026-42616)
Heap memory corruption when copying index data from root to an index
block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)
Single-byte heap buffer overflow when decompressing maliciously crafted
compressed file data. (CVE-2026-42618)
Heap buffer overflow when copying the tail data of an index block to a
freshly allocated block. (CVE-2026-46569)
Heap memory corruption for maliciously crafted or corrupt index data
descending to an out-of-bounds tree depth. (CVE-2026-46570)
Out-of-bounds read when processing symlink reparse data in a corrupt or
maliciously crafted filesystem. (CVE-2026-46571)
Heap buffer overflow for maliciously crafted or corrupt index data
during a node split. (CVE-2026-46572)
Heap buffer overflow when building inherited ACL data. (CVE-2026-56135)
Out of bounds access when clearing an index root in maliciously crafted
or corrupt index data. (CVE-2026-56136)
References
- https://bugs.mageia.org/show_bug.cgi?id=35940
- https://www.openwall.com/lists/oss-security/2026/07/15/6
- https://lists.debian.org/debian-security-announce/2026/msg00300.html
- https://ubuntu.com/security/notices/USN-8554-1
- https://www.cve.org/CVERecord?id=CVE-2026-42616
- https://www.cve.org/CVERecord?id=CVE-2026-42617
- https://www.cve.org/CVERecord?id=CVE-2026-42618
- https://www.cve.org/CVERecord?id=CVE-2026-46569
- https://www.cve.org/CVERecord?id=CVE-2026-46570
- https://www.cve.org/CVERecord?id=CVE-2026-46571
- https://www.cve.org/CVERecord?id=CVE-2026-46572
- https://www.cve.org/CVERecord?id=CVE-2026-56135
- https://www.cve.org/CVERecord?id=CVE-2026-56136
SRPMS
10/core
- ntfs-3g-2026.2.25-1.1.mga10
9/core
- ntfs-3g-2022.10.3-1.3.mga9