UbuntuUpdates.org

Package "libntfs-3g89t64"

Name: libntfs-3g89t64

Description:

read/write NTFS driver for FUSE (runtime library)

Latest version: 1:2022.10.3-1.2ubuntu3.2
Release: noble (24.04)
Level: security
Repository: main
Head package: ntfs-3g
Homepage: https://github.com/tuxera/ntfs-3g/wiki

Links


Download "libntfs-3g89t64"


Other versions of "libntfs-3g89t64" in Noble

Repository Area Version
base main 1:2022.10.3-1.2ubuntu3
updates main 1:2022.10.3-1.2ubuntu3.2

Changelog

Version: 1:2022.10.3-1.2ubuntu3.2 2026-07-16 13:09:12 UTC

  ntfs-3g (1:2022.10.3-1.2ubuntu3.2) noble-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in cat()
    - debian/patches/CVE-2026-42616.patch: Fix logic in ntfsprogs/ntfscat.c.
    - CVE-2026-42616
  * SECURITY UPDATE: buffer overflows and OOB read
    - debian/patches/CVE-2026-42617_46572_56136.patch: Fix logic in
      include/ntfs-3g/index.h, libntfs-3g/attrib.c, libntfs-3g/index.c.
    - CVE-2026-42617
    - CVE-2026-46572
    - CVE-2026-56136
  * SECURITY UPDATE: heap buffer overflow in ntfs_decompress()
    - debian/patches/CVE-2026-42618.patch: Fix logic in libntfs-3g/compress.c.
    - CVE-2026-42618
  * SECURITY UPDATE: heap buffer overflow in ntfs_ib_copy_tail()
    - debian/patches/CVE-2026-46569.patch: Fix logic in libntfs-3g/index.c.
    - CVE-2026-46569
  * SECURITY UPDATE: heap buffer overflow in ntfs_index_walk_down()
    - debian/patches/CVE-2026-46570.patch: Fix logic in libntfs-3g/index.c.
    - CVE-2026-46570
  * SECURITY UPDATE: out-of-bounds read in ntfs_fix_file_name()
    - debian/patches/CVE-2026-46571.patch: Fix logic in libntfs-3g/reparse.c.
    - CVE-2026-46571
  * SECURITY UPDATE: heap-based overflow in function build_inherited_id()
    - debian/patches/CVE-2026-56135.patch: Fix logic in include/ntfs-3g/acls.h,
      libntfs-3g/acls.c, libntfs-3g/security.c.
    - CVE-2026-56135

 -- Marc Deslauriers <email address hidden> Sat, 11 Jul 2026 11:55:48 -0400

Source diff to previous version

Version: 1:2022.10.3-1.2ubuntu3.1 2026-04-21 17:09:40 UTC

  ntfs-3g (1:2022.10.3-1.2ubuntu3.1) noble-security; urgency=medium

  * SECURITY UPDATE: use-after-free in ntfs_uppercase_mbs
    - debian/patches/CVE-2023-52890.patch: fix use-after-free in
      libntfs-3g/unistr.c.
    - CVE-2023-52890
  * SECURITY UPDATE: heap overflow in ntfs_build_permissions_posix()
    - debian/patches/CVE-2026-40706.patch: allocate space for the worst
      case number of ACE entries in libntfs-3g/acls.c.
    - CVE-2026-40706

 -- Marc Deslauriers <email address hidden> Fri, 17 Apr 2026 13:52:55 -0400

CVE-2023-52890 NTFS-3G before 75dcdc2 has a use-after-free in ntfs_uppercase_mbs in libntfs-3g/unistr.c. NOTE: discussion suggests that exploitation would be challe
CVE-2026-40706 Heap Buffer Overflow in ntfs_build_permissions_posix()



About   -   Send Feedback to @ubuntu_updates