Junglewise Threat Intelligence

CVE-2026-44070: Netatalk unbounded realloc in charset conversion

CVE-2026-44070 · Severity: low · CVSS 3.1 · Published 2026-05-21

Technologies: Netatalk team Netatalk.

Executive brief

Netatalk is an open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like systems to serve as file servers for macOS clients. A flaw in how the software handles character set conversions could allow an authenticated user to trigger excessive memory consumption. While difficult to exploit in practice due to existing system limits, it could potentially lead to a denial-of-service condition where the server becomes unresponsive.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in Netatalk's charset conversion logic. The software utilizes a retry loop that doubles the destination buffer size using 'realloc' without an explicit upper bound or overflow protection. An attacker with network access and valid credentials could attempt to trigger this loop to cause excessive memory allocation. However, exploitation is considered difficult (AC:H) because standard AFP path and string length limits typically constrain the growth before it reaches a critical level. The issue is resolved in version 4.5.0.

Affected products

  • Netatalk team Netatalk 2.0.0 through 4.4.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure date
  • 2026-05-21: advisory: NVD publication date
  • 2026-05-21: patched: Fixed in version 4.5.0

References