Advisories ยป MGASA-2026-0424

Updated ntfs-3g packages fix security vulnerabilities

Publication date: 20 Sep 2026
Modification date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136

Description

Heap memory corruption when processing a corrupt or maliciously crafted
filesystem. (CVE-2026-42616)
Heap memory corruption when copying index data from root to an index
block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)
Single-byte heap buffer overflow when decompressing maliciously crafted
compressed file data. (CVE-2026-42618)
Heap buffer overflow when copying the tail data of an index block to a
freshly allocated block. (CVE-2026-46569)
Heap memory corruption for maliciously crafted or corrupt index data
descending to an out-of-bounds tree depth. (CVE-2026-46570)
Out-of-bounds read when processing symlink reparse data in a corrupt or
maliciously crafted filesystem. (CVE-2026-46571)
Heap buffer overflow for maliciously crafted or corrupt index data
during a node split. (CVE-2026-46572)
Heap buffer overflow when building inherited ACL data. (CVE-2026-56135)
Out of bounds access when clearing an index root in maliciously crafted
or corrupt index data. (CVE-2026-56136)
                

References

SRPMS

10/core

9/core