UbuntuUpdates.org

Package "ntfs-3g"

Name: ntfs-3g

Description:

read/write NTFS driver for FUSE

Latest version: 1:2022.10.3-5ubuntu1.1
Release: resolute (26.04)
Level: security
Repository: main
Homepage: https://github.com/tuxera/ntfs-3g/wiki

Links


Download "ntfs-3g"


Other versions of "ntfs-3g" in Resolute

Repository Area Version
base main 1:2022.10.3-5build1
updates main 1:2022.10.3-5ubuntu1.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:2022.10.3-5ubuntu1.1 2026-07-16 13:09:16 UTC

  ntfs-3g (1:2022.10.3-5ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in cat()
    - debian/patches/CVE-2026-42616.patch: Fix logic in ntfsprogs/ntfscat.c.
    - CVE-2026-42616
  * SECURITY UPDATE: buffer overflows and OOB read
    - debian/patches/CVE-2026-42617_46572_56136.patch: Fix logic in
      include/ntfs-3g/index.h, libntfs-3g/attrib.c, libntfs-3g/index.c.
    - CVE-2026-42617
    - CVE-2026-46572
    - CVE-2026-56136
  * SECURITY UPDATE: heap buffer overflow in ntfs_decompress()
    - debian/patches/CVE-2026-42618.patch: Fix logic in libntfs-3g/compress.c.
    - CVE-2026-42618
  * SECURITY UPDATE: heap buffer overflow in ntfs_ib_copy_tail()
    - debian/patches/CVE-2026-46569.patch: Fix logic in libntfs-3g/index.c.
    - CVE-2026-46569
  * SECURITY UPDATE: heap buffer overflow in ntfs_index_walk_down()
    - debian/patches/CVE-2026-46570.patch: Fix logic in libntfs-3g/index.c.
    - CVE-2026-46570
  * SECURITY UPDATE: out-of-bounds read in ntfs_fix_file_name()
    - debian/patches/CVE-2026-46571.patch: Fix logic in libntfs-3g/reparse.c.
    - CVE-2026-46571
  * SECURITY UPDATE: heap-based overflow in function build_inherited_id()
    - debian/patches/CVE-2026-56135.patch: Fix logic in include/ntfs-3g/acls.h,
      libntfs-3g/acls.c, libntfs-3g/security.c.
    - CVE-2026-56135

 -- Marc Deslauriers <email address hidden> Sat, 11 Jul 2026 11:55:48 -0400

Source diff to previous version

Version: 1:2022.10.3-5ubuntu1 2026-04-27 13:11:06 UTC

  ntfs-3g (1:2022.10.3-5ubuntu1) resolute-security; urgency=medium

  * SECURITY UPDATE: heap overflow in ntfs_build_permissions_posix()
    - debian/patches/CVE-2026-40706.patch: allocate space for the worst
      case number of ACE entries in libntfs-3g/acls.c.
    - CVE-2026-40706

 -- Marc Deslauriers <email address hidden> Fri, 17 Apr 2026 13:48:50 -0400

CVE-2026-40706 Heap Buffer Overflow in ntfs_build_permissions_posix()



About   -   Send Feedback to @ubuntu_updates