[ubuntu/resolute-security] ntfs-3g 1:2022.10.3-5ubuntu1.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Jul 16 11:30:16 UTC 2026


ntfs-3g (1:2022.10.3-5ubuntu1.1) resolute-security; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in cat()
    - debian/patches/CVE-2026-42616.patch: Fix logic in ntfsprogs/ntfscat.c.
    - CVE-2026-42616
  * SECURITY UPDATE: buffer overflows and OOB read
    - debian/patches/CVE-2026-42617_46572_56136.patch: Fix logic in
      include/ntfs-3g/index.h, libntfs-3g/attrib.c, libntfs-3g/index.c.
    - CVE-2026-42617
    - CVE-2026-46572
    - CVE-2026-56136
  * SECURITY UPDATE: heap buffer overflow in ntfs_decompress()
    - debian/patches/CVE-2026-42618.patch: Fix logic in libntfs-3g/compress.c.
    - CVE-2026-42618
  * SECURITY UPDATE: heap buffer overflow in ntfs_ib_copy_tail()
    - debian/patches/CVE-2026-46569.patch: Fix logic in libntfs-3g/index.c.
    - CVE-2026-46569
  * SECURITY UPDATE: heap buffer overflow in ntfs_index_walk_down()
    - debian/patches/CVE-2026-46570.patch: Fix logic in libntfs-3g/index.c.
    - CVE-2026-46570
  * SECURITY UPDATE: out-of-bounds read in ntfs_fix_file_name()
    - debian/patches/CVE-2026-46571.patch: Fix logic in libntfs-3g/reparse.c.
    - CVE-2026-46571
  * SECURITY UPDATE: heap-based overflow in function build_inherited_id()
    - debian/patches/CVE-2026-56135.patch: Fix logic in include/ntfs-3g/acls.h,
      libntfs-3g/acls.c, libntfs-3g/security.c.
    - CVE-2026-56135

Date: 2026-07-11 16:27:11.046008+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list