{
  "schema_version": "1.7.0",
  "id": "MGASA-2026-0424",
  "published": "2026-09-20T04:25:32Z",
  "modified": "2026-09-20T02:49:52Z",
  "summary": "Updated ntfs-3g packages fix security vulnerabilities",
  "details": "Heap memory corruption when processing a corrupt or maliciously crafted\nfilesystem. (CVE-2026-42616)\nHeap memory corruption when copying index data from root to an index\nblock in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)\nSingle-byte heap buffer overflow when decompressing maliciously crafted\ncompressed file data. (CVE-2026-42618)\nHeap buffer overflow when copying the tail data of an index block to a\nfreshly allocated block. (CVE-2026-46569)\nHeap memory corruption for maliciously crafted or corrupt index data\ndescending to an out-of-bounds tree depth. (CVE-2026-46570)\nOut-of-bounds read when processing symlink reparse data in a corrupt or\nmaliciously crafted filesystem. (CVE-2026-46571)\nHeap buffer overflow for maliciously crafted or corrupt index data\nduring a node split. (CVE-2026-46572)\nHeap buffer overflow when building inherited ACL data. (CVE-2026-56135)\nOut of bounds access when clearing an index root in maliciously crafted\nor corrupt index data. (CVE-2026-56136)\n",
  "upstream": [
    "CVE-2026-42616",
    "CVE-2026-42617",
    "CVE-2026-42618",
    "CVE-2026-46569",
    "CVE-2026-46570",
    "CVE-2026-46571",
    "CVE-2026-46572",
    "CVE-2026-56135",
    "CVE-2026-56136"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2026-0424.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=35940"
    },
    {
      "type": "WEB",
      "url": "https://www.openwall.com/lists/oss-security/2026/07/15/6"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-security-announce/2026/msg00300.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://ubuntu.com/security/notices/USN-8554-1"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:10",
        "name": "ntfs-3g",
        "purl": "pkg:rpm/mageia/ntfs-3g?arch=source&distro=mageia-10"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2026.2.25-1.1.mga10"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "ntfs-3g",
        "purl": "pkg:rpm/mageia/ntfs-3g?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2022.10.3-1.3.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
