Junglewise Threat Intelligence

CVE-2026-44067: Netatalk heap over-read in extended attribute header parsing

CVE-2026-44067 · Severity: medium · CVSS 4.2 · Published 2026-05-21

Technologies: Netatalk. Vendors: Netatalk.

Executive brief

Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) that allows Unix-like systems to serve files to macOS clients. A vulnerability in how it handles file metadata could allow an attacker with existing access to cause a system crash or read sensitive information from the server's memory. This issue is primarily a risk if the server's metadata files are modified by another process or user, potentially leading to service instability.

Technical details

A heap-based out-of-bounds read (CWE-125) exists in Netatalk's AppleDouble metadata parsing logic. The vulnerability occurs because the extended attribute header parsing routine trusts the on-disk entry count without validating it against the actual buffer size. An attacker with low privileges and the ability to influence metadata (e.g., via NFS, Samba, or local access) can trigger this over-read. While the risk of remote code execution is low, the flaw can be used to crash the service or leak memory contents. The issue is fixed in version 4.5.0.

Affected products

  • Netatalk Netatalk 2.1.0 through 4.4.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure date
  • 2026-05-21: advisory: NVD publication date
  • 2026-05-21: patched: Fixed in version 4.5.0

References

Related threats