|
|
Log in / Subscribe / Register

Ubuntu alert USN-8554-1 (ntfs-3g)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8554-1] NTFS-3G vulnerabilities
Date:  Thu, 16 Jul 2026 13:08:27 +0000
Message-ID:  <E1wkLpD-0003q0-5p@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8554-1 July 16, 2026 ntfs-3g vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in NTFS-3G. Software Description: - ntfs-3g: read/write NTFS driver for FUSE Details: It was discovered that NTFS-3G had a heap buffer overflow when reading certain NTFS images. A local attacker could possibly use this issue to execute arbitrary code. (CVE-2026-42616) It was discovered that NTFS-3G had multiple heap buffer overflows when processing certain NTFS images. A local attacker could possibly use these issues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135) It was discovered that NTFS-3G had out-of-bounds reads when processing certain NTFS images. A local attacker could possibly use these issues to obtain sensitive information. (CVE-2026-46571, CVE-2026-56136) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libntfs-3g89t64 1:2022.10.3-5ubuntu1.1 ntfs-3g 1:2022.10.3-5ubuntu1.1 Ubuntu 24.04 LTS libntfs-3g89t64 1:2022.10.3-1.2ubuntu3.2 ntfs-3g 1:2022.10.3-1.2ubuntu3.2 Ubuntu 22.04 LTS libntfs-3g89 1:2021.8.22-3ubuntu1.4 ntfs-3g 1:2021.8.22-3ubuntu1.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8554-1 CVE-2026-42616, CVE-2026-42617, CVE-2026-42618, CVE-2026-46569, CVE-2026-46570, CVE-2026-46571, CVE-2026-46572, CVE-2026-56135, CVE-2026-56136 Package Information: https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-... https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-... https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpY100ACgkQcpJm3tlz hgEy+A/+JjNMumB7WDkBu3c+Li+VeRx5E/uplZWHzVncRZt/YWg7K7QZ/W7SjQwq 8h/Vl2+3z94DsuEdsGcGyA5m/qQ4xE4j8fUBwOGhQzsx0qVX8LvczclNVsIiyHbV 0hIkjosLJrvygBuD2G0Uh0yrOAdHeEC06/VbnRhsd1T9I/g0BcNy/0OB61HGcuJo dx44BFEWxoAjVtqF2D5UbTAdMPdZjOw+Lq9a6lT2LMwD5nqIOKdhqinIAXGdAdv0 JWoxVO3zGO16Sz1Qn/Ht4wKVEKufQktzRvjmZqXUKoBDk23SiqESpK2RXlksBRup jJrqftAsQFeWB7jc8iAL0IGqNi6E8vnh0H0nv355kplBpYmnfoi6ApE7vMVI0wVx DpjH0KoUd23H4IYMnVp8z+9CUx15ux7k1SwAkxJ051BLohz5lDWSYJ3ZFxAauI/T u00zuIEOjIhI82aBoK2U6cx51S/zmK/M2Qy5K4/IERuGy30eDwkHSqZBO1a3/TY+ hUwxM5zHiZv9Yp5X5N+zC+2YhbM/fCChAqoXJRdNyP5KMM3vuWIOtUF53yG7lS9n JByDuoX3/ER+mxWDkhSH3Twmaj+Mxufg+OcHBhUOLcpVAmexEajOK1YELIezUe15 FD/wis+oxHqhsSPa04pCEyLjKz8/XT1IgUZiHYcacipvPGzqrC8= =WVWf -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds