Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) used to allow Linux and Unix systems to act as file servers for macOS clients. A security flaw in how the software handles user identity data allows an authenticated user to execute unauthorized commands on the server. This could lead to a full system compromise or unauthorized access to sensitive files stored on the network share.
Technical details
A vulnerability exists in Netatalk versions 3.1.4 through 4.4.2 due to a bitwise-OR logic error in the handling of file change event (FCE) notifications. When FCE event command integrations are active, user identity data is appended to shell commands without proper escaping or neutralization. An authenticated attacker with an active AFP session can exploit this to achieve OS command injection, potentially executing arbitrary code with the privileges of the session user. The attack requires a specific configuration where 'fce notify script' is enabled in afp.conf and may be more prevalent in environments backed by directory services. The issue is resolved in version 4.4.3.
Affected products
- Netatalk Project Netatalk 3.1.4 through 4.4.2
Timeline
- 2026-05-13: disclosed: Initial disclosure date reported by vendor
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Fixed in version 4.4.3