Your message dated Sat, 18 Jul 2026 15:00:17 +0000
with message-id <[email protected]>
and subject line Bug#1142144: fixed in ntfs-3g 1:2026.7.7-1
has caused the Debian Bug report #1142144,
regarding ntfs-3g: CVE-2026-42616 CVE-2026-42617 CVE-2026-42618 CVE-2026-46569
CVE-2026-46570 CVE-2026-46571 CVE-2026-46572 CVE-2026-56135 CVE-2026-56136
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142144: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142144
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ntfs-3g
Version: 1:2026.2.25-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for ntfs-3g.
CVE-2026-42616[0], CVE-2026-42617[1], CVE-2026-42618[2],
CVE-2026-46569[3], CVE-2026-46570[4], CVE-2026-46571[5],
CVE-2026-46572[6], CVE-2026-56135[7], CVE-2026-56136[8].
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-42616
https://www.cve.org/CVERecord?id=CVE-2026-42616
[1] https://security-tracker.debian.org/tracker/CVE-2026-42617
https://www.cve.org/CVERecord?id=CVE-2026-42617
[2] https://security-tracker.debian.org/tracker/CVE-2026-42618
https://www.cve.org/CVERecord?id=CVE-2026-42618
[3] https://security-tracker.debian.org/tracker/CVE-2026-46569
https://www.cve.org/CVERecord?id=CVE-2026-46569
[4] https://security-tracker.debian.org/tracker/CVE-2026-46570
https://www.cve.org/CVERecord?id=CVE-2026-46570
[5] https://security-tracker.debian.org/tracker/CVE-2026-46571
https://www.cve.org/CVERecord?id=CVE-2026-46571
[6] https://security-tracker.debian.org/tracker/CVE-2026-46572
https://www.cve.org/CVERecord?id=CVE-2026-46572
[7] https://security-tracker.debian.org/tracker/CVE-2026-56135
https://www.cve.org/CVERecord?id=CVE-2026-56135
[8] https://security-tracker.debian.org/tracker/CVE-2026-56136
https://www.cve.org/CVERecord?id=CVE-2026-56136
Prepared a trixie-security version to be released shortly with the
patches upstrem provided specifically for the 2022.10.3 version.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: ntfs-3g
Source-Version: 1:2026.7.7-1
Done: Laszlo Boszormenyi (GCS) <[email protected]>
We believe that the bug you reported is fixed in the latest version of
ntfs-3g, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <[email protected]> (supplier of updated ntfs-3g package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 15 Jul 2026 22:16:05 +0200
Source: ntfs-3g
Binary: libntfs-3g90 libntfs-3g90-dbgsym ntfs-3g ntfs-3g-dbgsym ntfs-3g-dev
ntfs-3g-dev-dbgsym ntfs-3g-udeb
Architecture: source amd64
Version: 1:2026.7.7-1
Distribution: experimental
Urgency: medium
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Laszlo Boszormenyi (GCS) <[email protected]>
Description:
libntfs-3g90 - read/write NTFS driver for FUSE (runtime library)
ntfs-3g - read/write NTFS driver for FUSE
ntfs-3g-dev - read/write NTFS driver for FUSE (development)
ntfs-3g-udeb - read/write NTFS driver for FUSE (udeb)
Closes: 1142144
Changes:
ntfs-3g (1:2026.7.7-1) experimental; urgency=medium
.
* New upstream release (closes: #1142144):
- fixes CVE-2026-42616: heap buffer overflow in cat(),
- fixes CVE-2026-42617: heap buffer overflow in ntfs_ir_to_ib(),
- fixes CVE-2026-42618: heap buffer overflow in ntfs_decompress(),
- fixes CVE-2026-46569: missing range check in ntfs_ib_copy_tail(),
- fixes CVE-2026-46570: heap memory corruption in ntfs_index_walk_down(),
- fixes CVE-2026-46571: out of bounds read in ntfs_fix_file_name(),
- fixes CVE-2026-46572: heap buffer overflow in ntfs_ib_cut_tail(),
- fixes CVE-2026-56135: heap buffer overflow in build_inherited_id(),
- fixes CVE-2026-56136: out of bounds memmove in ntfs_ir_nill().
* Update copyright file.
* Update Standards-Version to 4.7.2 .
* Library transition from libntfs-3g89 to libntfs-3g90 .
Checksums-Sha1:
a1c1179be16f16d662c6062268154055b6877f87 2027 ntfs-3g_2026.7.7-1.dsc
859be51257057622079873266b2007c9977253b1 904838 ntfs-3g_2026.7.7.orig.tar.gz
74c18c2ca28c25ec4d1e35b4a93d07c6c0b71234 24124 ntfs-3g_2026.7.7-1.debian.tar.xz
31ec0adc1813ab25d415f9a72e44e634bc83a0a3 425680
libntfs-3g90-dbgsym_2026.7.7-1_amd64.deb
baea936b15640fe10db70c2bfb939f58907637d1 168792
libntfs-3g90_2026.7.7-1_amd64.deb
30996c0dbb31e0d3d4950494d1c00a22b36833b3 1333188
ntfs-3g-dbgsym_2026.7.7-1_amd64.deb
0ef8739aab6b76bcdd676ea91f4d3ec2f8fe0e18 73812
ntfs-3g-dev-dbgsym_2026.7.7-1_amd64.deb
d1750a4a942ab33e9158f6f48a41e993dd5ad67d 247052
ntfs-3g-dev_2026.7.7-1_amd64.deb
04e83a0fe8fe1d7734863c62c32cb9a049b6b566 236272
ntfs-3g-udeb_2026.7.7-1_amd64.udeb
41fe0e524bb70aed0b72aaae5161f0058e1d867a 8308
ntfs-3g_2026.7.7-1_amd64.buildinfo
ddd8b6b310b955359bc9a559051904d6e633ec0b 416160 ntfs-3g_2026.7.7-1_amd64.deb
Checksums-Sha256:
1ac69ee0c17480a2472da37634fc48877256ac4278c94c66d6eabd7c6308e97c 2027
ntfs-3g_2026.7.7-1.dsc
7742bfe3399a7b2f677fea8aa193dc21d38112d77ae8beb0fb66aaf550f72c1d 904838
ntfs-3g_2026.7.7.orig.tar.gz
d499cb59484b8faa1f302ad21ab729eed08212333ba5a11f9c318f3b9dec15cc 24124
ntfs-3g_2026.7.7-1.debian.tar.xz
967d610d8adcfb9a1a415ea51f5aada3c18ad4503cabc46c10e0f07eaea307f4 425680
libntfs-3g90-dbgsym_2026.7.7-1_amd64.deb
056ca26549153bed0f014c11793f3ad453eb663feeed866939b5568cfd53503b 168792
libntfs-3g90_2026.7.7-1_amd64.deb
0a49b7b5fd1ddc6b0fcba58b04ac42d38039831662d6b267b3275349ca84085d 1333188
ntfs-3g-dbgsym_2026.7.7-1_amd64.deb
a39c5d330474b2ae962b854db6044cb248faf3b3181652ae29dcafe739e17d2f 73812
ntfs-3g-dev-dbgsym_2026.7.7-1_amd64.deb
3d79180494f3a63a57c0c66c05ca2382a090fc80341fbd9bb88a765275602004 247052
ntfs-3g-dev_2026.7.7-1_amd64.deb
f58bab378983057f83ec4188c89b1868577b2f33aa062789738c7e54b6ade086 236272
ntfs-3g-udeb_2026.7.7-1_amd64.udeb
7ffc0457e539e5aed9d85423b2e91b38749f3df664bc97534c8855b40bb7db88 8308
ntfs-3g_2026.7.7-1_amd64.buildinfo
93391ce9dd5fb6126d0897dc8b02f0e30ecacee368aa12bac6600507dcea1ddd 416160
ntfs-3g_2026.7.7-1_amd64.deb
Files:
d685bfbfc0bd0105833189325a35a15f 2027 otherosfs optional ntfs-3g_2026.7.7-1.dsc
254f0eae638ae2f1f0e24f0b76dd1dfc 904838 otherosfs optional
ntfs-3g_2026.7.7.orig.tar.gz
03bc4b021b583a6fad11f2ce6c4f602f 24124 otherosfs optional
ntfs-3g_2026.7.7-1.debian.tar.xz
66753fa4061015e658bafaad948716e1 425680 debug optional
libntfs-3g90-dbgsym_2026.7.7-1_amd64.deb
66746f9e1db3791d200e370c40109db8 168792 libs optional
libntfs-3g90_2026.7.7-1_amd64.deb
e2be890818e579a078e6293b5d4ded85 1333188 debug optional
ntfs-3g-dbgsym_2026.7.7-1_amd64.deb
085e2b4d05f0f914362641879563a7a0 73812 debug optional
ntfs-3g-dev-dbgsym_2026.7.7-1_amd64.deb
951afd54febc103daf413ae5f27d9fe4 247052 libdevel optional
ntfs-3g-dev_2026.7.7-1_amd64.deb
a22cfa571b18a68a53037541c240b1fc 236272 debian-installer optional
ntfs-3g-udeb_2026.7.7-1_amd64.udeb
fda3eab868ca7c11dd4f1ab376333a57 8308 otherosfs optional
ntfs-3g_2026.7.7-1_amd64.buildinfo
f289b61fc38a2c3092247de71fb19966 416160 otherosfs optional
ntfs-3g_2026.7.7-1_amd64.deb
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmpY+24ACgkQ3OMQ54ZM
yL9ZdQ//dwxywmN1JVJs87l0xSiOvKn8DAT0LUQJcnFGHob3lL2ongXZcwyMYedK
y6yvQ97phhX4JDpq/QleSMzYCZ8zMvE6NsNZifpVd9lE/eoSjT6Asx+YXn8jK3Ir
hPFfgcdqufkhJAfKoo5zkNVxl3TUC9k6eC2nW/A1AuPnolNEd8R1axN856lKkABQ
J3IRZkvWNZhpbxv9wO+VH3KIRflmT8/ivsWk8rLnt6y0EqE4e6g8NvRjlnPX1TxQ
MelMyxZIULcCQqSIFD+oAYD7yqUJm2jXYJOGLJUyYuK0Dhe1WWofie203E2r81vN
hX6kKZKrEKBzvXx8mp7Vug8QgptnIRY53kpO/Qo9yCDo/j0VapOo95v9tghZc/7+
5C4YUJjy+W0rGdpq2MlzmTZ0wDvzvebCHl+k5cOTXJ0UUN7Q4tn+TzBhxWA/h89Q
vGcQoCIzrooQYwXcclvZa7a3Z/uD0TMqrrQkK8zfm9L5aus+XTzPVUC/L+hqIfpi
QuYNJEcOcM956sEuUHWX60gbCNaHY/NevFFruvbah/1ooivD+EVTSld5v0wbkbD6
XGFgKd8rL6o6rLB/sUCPgtCPEUZ/0J7Oi4PGOG9MzhKpteBNKp9JfpKRpAoF4LNG
UBoqN4J5w8GkVai2C2pUA9HkDOg54OAJLx2hSv8zA5xxZQeoNeI=
=1pxq
-----END PGP SIGNATURE-----
pgpPH2YBcn4EI.pgp
Description: PGP signature
--- End Message ---