Security Release 2026.9.18 (September 23, 2026)
Download: https://tuxera.com/opensource/ntfs-3g_ntfsprogs-2026.9.18.tgz
Checksums:
SHA-256: bcf3cf301a79e42d330128ffb52d4cf615bd1d30c10a92d9d8d14f2bb4fcd9bf
SHA-512: 2c31e346dcfe1448ee829e4d66d27a8703304dd107cd18e1902708703f83fa2448d9d816406ef17d37157cddbb5685546455d56f432627292239e0dbf63c9dde6e0386aebe8b66522d90cdc2
Changes:
- Guard against multiple creator-owner and creator-group ACEs during ACL inheritance.
- (ntfscat) Fix missing cleanup of opened attribute on error (#212).
- Fix heap out of bounds read/write in
ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv) - Fix heap data corruption in
ntfs_mapping_pairs_decompress_i(). (GHSA-mc3c-983p-wqm8) - Fix heap buffer overflow in
ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3) - Fix heap buffer overflow in
ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8) - Fix heap buffer overflow in
ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x) - Fix denial-of-service in
ntfs_inode_attach_all_extents(). (GHSA-jcjj-9262-6j6p) - Fix heap buffer overflow in
ntfs_same_sid(). (GHSA-x98j-3g35-f59x) - Fix heap buffer overflow in
ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72) - (ntfsresize) Fix stale
$MFTMirrdata when the first extent of$MFTis relocated. (issue #209).
In addition to the NTFS-3G team, we'd like to thank Jurre van Bergen and France's Cybersecurity Agency (ANSSI) for contributing to this release with security reports.
If you have a security issue to report for ntfs-3g, then please follow the process outlined here:
https://www.tuxera.com/security-advisories/