Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package ntfs-3g_ntfsprogs for
openSUSE:Factory checked in at 2026-07-29 18:58:19
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/ntfs-3g_ntfsprogs (Old)
and /work/SRC/openSUSE:Factory/.ntfs-3g_ntfsprogs.new.2004 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "ntfs-3g_ntfsprogs"
Wed Jul 29 18:58:19 2026 rev:37 rq:1367924 version:2026.7.7
Changes:
--------
--- /work/SRC/openSUSE:Factory/ntfs-3g_ntfsprogs/ntfs-3g_ntfsprogs.changes
2026-07-21 22:54:53.662414748 +0200
+++
/work/SRC/openSUSE:Factory/.ntfs-3g_ntfsprogs.new.2004/ntfs-3g_ntfsprogs.changes
2026-07-29 18:58:31.996163649 +0200
@@ -1,0 +2,35 @@
+Wed Jul 22 23:42:55 UTC 2026 - Michael Gorse <[email protected]>
+
+- Update to version 2026.7.7:
+ * (ntfscat) Fix heap memory corruption when processing a corrupt
+ or maliciously crafted filesystem. (CVE-2026-42616).
+ * Fix heap memory corruption when copying index data from root to
+ an index block in a corrupt or maliciously crafted filesystem.
+ (CVE-2026-42617).
+ * Fix single-byte heap buffer overflow when decompressing
+ maliciously crafted compressed file data. (CVE-2026-42618).
+ * Fix heap buffer overflow when copying the tail data of an index
+ block to a freshly allocated block. (CVE-2026-46569).
+ * Fix out-of-bounds read when processing symlink reparse data in
+ a corrupt or maliciously crafted filesystem. (CVE-2026-46571).
+ * Fix heap memory corruption for maliciously crafted or corrupt
+ index data descending to an out-of-bounds tree depth.
+ (CVE-2026-46570).
+ * Fix heap buffer overflow for maliciously crafted or corrupt
+ index data during a node split. (CVE-2026-46572).
+ * Fix heap buffer overflow when building inherited ACL data.
+ (CVE-2026-56135).
+ * Fix out of bounds access when clearing an index root in
+ maliciously crafted or corrupt index data. (CVE-2026-56136).
+- Drop patches fixed upstream:
+ + ntfs3g-unistr-use-after-free.patch
+ + ntfs3g-heap-overflow.patch
+ + 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch
+ + 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch
+ + 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch
+ + 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch
+ + 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch
+ + 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch
+ + 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch
+
+-------------------------------------------------------------------
Old:
----
1_ntfs-3g_2022.10.3-CVE-2026-42618.patch
2_ntfs-3g_2022.10.3-CVE-2026-42616.patch
3_ntfs-3g_2022.10.3-CVE-2026-42617.patch
4_ntfs-3g_2022.10.3-CVE-2026-46569.patch
5_ntfs-3g_2022.10.3-CVE-2026-46571.patch
6_ntfs-3g_2022.10.3-CVE-2026-46570.patch
8_ntfs-3g_2022.10.3-CVE-2026-56135.patch
ntfs-3g_ntfsprogs-2022.10.3.tgz
ntfs3g-heap-overflow.patch
ntfs3g-unistr-use-after-free.patch
New:
----
ntfs-3g_ntfsprogs-2026.7.7.tgz
----------(Old B)----------
Old: + ntfs3g-heap-overflow.patch
+ 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch
+ 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch
Old: + 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch
+ 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch
+ 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch
Old: + 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch
+ 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch
+ 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch
Old: + 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch
+ 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch
+ 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch
Old: + 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch
+ 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch
+ 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch
Old: + 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch
+ 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch
+ 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch
Old: + 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch
+ 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch
Old: + ntfs3g-unistr-use-after-free.patch
+ ntfs3g-heap-overflow.patch
+ 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch
Old:- Drop patches fixed upstream:
+ ntfs3g-unistr-use-after-free.patch
+ ntfs3g-heap-overflow.patch
----------(Old E)----------
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ ntfs-3g_ntfsprogs.spec ++++++
--- /var/tmp/diff_new_pack.z2Z2Hm/_old 2026-07-29 18:58:34.364245328 +0200
+++ /var/tmp/diff_new_pack.z2Z2Hm/_new 2026-07-29 18:58:34.384246018 +0200
@@ -16,35 +16,20 @@
#
-%define sover 89
+%define sover 90
%if 0%{?suse_version} >= 1550
%define sbindir %{_sbindir}
%else
%define sbindir /sbin
%endif
Name: ntfs-3g_ntfsprogs
-Version: 2022.10.3
+Version: 2026.7.7
Release: 0
Summary: NTFS Support in Userspace
License: GPL-2.0-or-later
Group: System/Filesystems
URL: https://github.com/tuxera/ntfs-3g/
Source: https://tuxera.com/opensource/%{name}-%{version}.tgz
-# PATCH-FIX-UPSTREAM ntfs3g-unistr-use-after-free.patch boo#1226007
[email protected] -- fix use after free in ntfs_uppercase_mbs.
-Patch0: ntfs3g-unistr-use-after-free.patch
-# PATCH-FIX-UPSTREAM ntfs3g-heap-overflow.patch bsc#1262216 [email protected]
-- fix heap overflow
-Patch1: ntfs3g-heap-overflow.patch
-Patch2: 1_ntfs-3g_2022.10.3-CVE-2026-42618.patch
-Patch3: 2_ntfs-3g_2022.10.3-CVE-2026-42616.patch
-Patch4: 3_ntfs-3g_2022.10.3-CVE-2026-42617.patch
-Patch5: 4_ntfs-3g_2022.10.3-CVE-2026-46569.patch
-Patch6: 5_ntfs-3g_2022.10.3-CVE-2026-46571.patch
-Patch7: 6_ntfs-3g_2022.10.3-CVE-2026-46570.patch
-# This is the same as 3_...42617.patch
-#Patch8: 7_ntfs-3g_2022.10.3-CVE-2026-46572.patch
-Patch9: 8_ntfs-3g_2022.10.3-CVE-2026-56135.patch
-# This is the same as 3_...42617.patch
-#Patch10: 9_ntfs-3g_2022.10.3-CVE-2026-56136.patch
BuildRequires: gnutls-devel
BuildRequires: hwinfo-devel
BuildRequires: libgcrypt-devel
@@ -120,7 +105,7 @@
They have been orphaned for ten years and are unlikely to be upgraded (except
ntfsfallocate, if there is some demand).
%prep
-%autosetup -p1
+%autosetup -n ntfs-3g-%{version} -p1
%build
#
++++++ ntfs-3g_ntfsprogs-2022.10.3.tgz -> ntfs-3g_ntfsprogs-2026.7.7.tgz ++++++
++++ 20867 lines of diff (skipped)