Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) used to allow non-Apple systems to act as file servers for Mac computers. A flaw in how the software manages user permissions could potentially allow a local user to interfere with security controls. While the risk of a remote attack is considered low, the issue weakens the overall security of the file server's privilege management system.
Technical details
Netatalk versions 2.2.5 through 4.4.2 contain a race condition (CWE-362) within its privilege-switching logic. The software utilizes shared global state for toggling privileges without adequate locking or support for nested execution. This non-reentrant behavior means that concurrent or nested calls to privilege-management functions could lead to inconsistent security states. While the maintainers have not identified a direct path for remote privilege escalation in standard afpd request handling, the flaw represents a failure in robust privilege separation. The issue is resolved in version 4.5.0.
Affected products
- Netatalk Netatalk 2.2.5 through 4.4.2
Timeline
- 2026-05-13: disclosed
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Fixed in version 4.5.0