Executive brief
Netatalk, an open-source implementation of the Apple Filing Protocol (AFP) used to share files with macOS clients, contains a security flaw in how it handles file metadata. An authorized user could bypass directory restrictions to create, modify, or delete files they should not have access to. This could lead to unauthorized data modification or loss of system integrity on the file server.
Technical details
A path traversal vulnerability (CWE-22) exists in Netatalk versions 2.1.0 through 4.4.2 due to incomplete sanitization of extended attribute (EA) names when stored as AppleDouble files. When processing EA file operations, the software fails to consistently confine client-controlled names to the designated metadata namespace. An authenticated attacker with network access to the AFP service can exploit this to create, modify, remove, or change permissions of files on the underlying filesystem, limited by the permissions of the user account running the service. The issue is resolved in version 4.4.3.
Affected products
- Netatalk Netatalk 2.1.0 through 4.4.2
Timeline
- 2026-05-13: disclosed
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Fixed in version 4.4.3