Fedora 46 : ntfs-3g / ntfs-3g-system-compression / partclone / testdisk / etc (2026-a2beb6a664)

high Nessus Plugin ID 350320

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 46 host has packages installed that are affected by a vulnerability as referenced in the FEDORA-2026-a2beb6a664 advisory.

ntfs-3g changes:

Guard against multiple creator-owner and creator-group ACEs during ACL inheritance.
(ntfscat) Fix missing cleanup of opened attribute on error (issue #212).
Fix heap out of bounds read/write in ntfs_ie_add_vcn(). (GHSA-r6xj-6488-p8mv, CVE pending) Fix heap data corruption in ntfs_mapping_pairs_decompress_i(). (GHSA-mc3c-983p-wqm8, CVE pending) Fix heap buffer overflow in ntfs_external_attr_find(). (GHSA-wf3w-fjjg-x4w3, CVE pending) Fix heap buffer overflow in ntfs_ea_check_wsldev(). (GHSA-2c97-47cr-9xr8, CVE pending) Fix heap buffer overflow in ntfs_check_restart_area(). (GHSA-xrvx-6jrp-4q3x, CVE pending) Fix denial-of-service in ntfs_inode_attach_all_extents(). (GHSA-jcjj-9262-6j6p, CVE pending) Fix heap buffer overflow in ntfs_same_sid(). (GHSA-x98j-3g35-f59x, CVE pending) Fix heap buffer overflow in ntfs_acl_owner(). (GHSA-pc48-m7cx-qf72, CVE pending) (ntfsresize) Fix stale $MFTMirr data when the first extent of $MFT is relocated (issue #209).

Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2026-a2beb6a664

Plugin Details

Severity: High

ID: 350320

File Name: fedora_2026-a2beb6a664.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/25/2026

Updated: 9/25/2026

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:46, p-cpe:/a:fedoraproject:fedora:ntfs-3g-system-compression, p-cpe:/a:fedoraproject:fedora:ntfs-3g, p-cpe:/a:fedoraproject:fedora:partclone, p-cpe:/a:fedoraproject:fedora:testdisk, p-cpe:/a:fedoraproject:fedora:wimlib

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/25/2026

Vulnerability Publication Date: 9/25/2026

Reference Information