Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol used to allow non-Apple systems to serve files and print services to Mac clients. A flaw in the legacy AppleTalk printing component could allow an attacker on the same local network to crash the printing service. While the risk of data theft is low, an exploit could disrupt printing operations for users relying on these legacy services.
Technical details
An off-by-two error (CWE-193) exists in the `lp_write()` function within the `papd` (Printer Access Protocol Daemon) component of Netatalk. When handling printer data under specific translated-input conditions, the application can write up to two bytes beyond the boundaries of a temporary buffer. The vulnerability is reachable over the network (adjacent vector) if the AppleTalk printing configuration is enabled. While the complexity of exploitation is high, a successful attack primarily results in a denial of service. The issue is resolved in Netatalk version 4.5.0, and a source patch is available for version 4.4.2.
Affected products
- Netatalk team Netatalk 2.0.0 through 4.4.2
Timeline
- 2026-05-13: disclosed
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Fixed in version 4.5.0