Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like systems to serve as file servers for macOS clients. A critical vulnerability in the CNID daemon component could allow an attacker to crash the file service or potentially execute unauthorized code. This could lead to a total loss of availability for network shares and compromise the security of the hosting server.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Netatalk CNID daemon within the comm_rcv() function. The vulnerability is caused by the daemon trusting a client-supplied name length value, leading it to read attacker-controlled data into a fixed-size buffer. An authenticated attacker with network access to the CNID service can exploit this to overflow daemon memory. This can result in a denial-of-service (service crash) or potentially arbitrary code execution with the privileges of the daemon. The issue is resolved in version 4.4.3, and a workaround involves switching to the 'sqlite' CNID backend.
Affected products
- Netatalk team Netatalk 2.0.0 through 4.4.2
Timeline
- 2026-05-13: disclosed: Initial disclosure date reported by vendor
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Version 4.4.3 released with fix