{"id":"SUSE-SU-2026:3214-1","summary":"Security update for ntfs-3g_ntfsprogs","details":"This update for ntfs-3g_ntfsprogs fixes the following issues\n\n- CVE-2026-42616: heap buffer overflow in `cat()` of `cat.c` can lead to heap corruption in the ntfscat binary via a\n  specially crafted NTFS image (bsc#1271102).\n- CVE-2026-42617: heap buffer overflow in `ntfs_ir_to_ib()` of `index.c` can lead to heap corruption in the SUID-root\n  ntfs-3g binary via a specially crafted NTFS image (bsc#1271103).\n- CVE-2026-42618: heap buffer overflow in `ntfs_decompress()` of `compress.c` can lead to heap corruption in the\n  SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271104).\n- CVE-2026-46569: heap buffer overflow in `ntfs_ib_copy_tail()` of `libntfs-3g/index.c`can lead to heap corruption in\n  the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271105).\n- CVE-2026-46570: heap buffer overflow in `ntfs_index_walk_down()` of `libntfs-3g/index.c` can lead to heap corruption\n  in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271106).\n- CVE-2026-46571: out-of-bounds read in `ntfs_fix_file_name()` of `libntfs-3g/reparse.c` can lead to disclosure of\n  confidential information from the ntfs-3g process memory when handling a specially crafted NTFS image (bsc#1271107).\n- CVE-2026-46572: heap buffer overflow in `ntfs_ib_cut_tail()` of `libntfs-3g/index.c` can lead to heap corruption\n  in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271108).\n- CVE-2026-56135: heap-based buffer overflow in `build_inherited_id()` of `libntfs-3g/security.c` can lead to heap\n  corruption in the SUID-root ntfs-3g binary via a specially crafted NTFS image (bsc#1271109).\n- CVE-2026-56136: out-of-bounds read in `ntfs_ir_nill()` of `libntfs-3g/index.c` can lead to disclosure of \n  confidential information from the ntfs-3g process memory when handling a specially crafted NTFS image (bsc#1271110).\n","modified":"2026-07-24T17:15:13.040361455Z","published":"2026-07-23T14:18:48Z","related":["CVE-2026-42616","CVE-2026-42617","CVE-2026-42618","CVE-2026-46569","CVE-2026-46570","CVE-2026-46571","CVE-2026-46572","CVE-2026-56135","CVE-2026-56136"],"upstream":["CVE-2026-42616","CVE-2026-42617","CVE-2026-42618","CVE-2026-46569","CVE-2026-46570","CVE-2026-46571","CVE-2026-46572","CVE-2026-56135","CVE-2026-56136"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263214-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271102"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271103"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271104"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271105"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271106"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271107"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271108"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271109"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271110"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42616"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46569"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46570"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46571"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46572"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56136"}],"affected":[{"package":{"name":"ntfs-3g_ntfsprogs","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/ntfs-3g_ntfsprogs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2022.5.17-150000.3.27.1"}]}],"ecosystem_specific":{"binaries":[{"libntfs-3g87":"2022.5.17-150000.3.27.1","ntfs-3g":"2022.5.17-150000.3.27.1","ntfsprogs":"2022.5.17-150000.3.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3214-1.json"}},{"package":{"name":"ntfs-3g_ntfsprogs","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/ntfs-3g_ntfsprogs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2022.5.17-150000.3.27.1"}]}],"ecosystem_specific":{"binaries":[{"libntfs-3g-devel":"2022.5.17-150000.3.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3214-1.json"}},{"package":{"name":"ntfs-3g_ntfsprogs","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/ntfs-3g_ntfsprogs&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2022.5.17-150000.3.27.1"}]}],"ecosystem_specific":{"binaries":[{"libntfs-3g87":"2022.5.17-150000.3.27.1","ntfs-3g":"2022.5.17-150000.3.27.1","ntfsprogs":"2022.5.17-150000.3.27.1","libntfs-3g-devel":"2022.5.17-150000.3.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3214-1.json"}},{"package":{"name":"ntfs-3g_ntfsprogs","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/ntfs-3g_ntfsprogs&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2022.5.17-150000.3.27.1"}]}],"ecosystem_specific":{"binaries":[{"libntfs-3g-devel":"2022.5.17-150000.3.27.1","libntfs-3g87":"2022.5.17-150000.3.27.1","ntfs-3g":"2022.5.17-150000.3.27.1","ntfsprogs":"2022.5.17-150000.3.27.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3214-1.json"}}],"schema_version":"1.7.5"}