MGASA-2026-0424

Source
https://advisories.mageia.org/MGASA-2026-0424.html
Import Source
https://advisories.mageia.org/MGASA-2026-0424.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0424
Upstream
  • CVE-2026-42616
  • CVE-2026-42617
  • CVE-2026-42618
  • CVE-2026-46569
  • CVE-2026-46570
  • CVE-2026-46571
  • CVE-2026-46572
Published
2026-09-20T04:25:32Z
Modified
2026-09-20T04:30:03Z
Summary
Updated ntfs-3g packages fix security vulnerabilities
Details

Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136)

References
Credits

Affected packages

Mageia:10 / ntfs-3g

Package

Name
ntfs-3g
Purl
pkg:rpm/mageia/ntfs-3g?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.25-1.1.mga10

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0424.json"

Mageia:9 / ntfs-3g

Package

Name
ntfs-3g
Purl
pkg:rpm/mageia/ntfs-3g?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2022.10.3-1.3.mga9

Ecosystem specific

{
    "section":  "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0424.json"