Executive brief
Netatalk, an open-source implementation of the Apple Filing Protocol (AFP) used for file sharing, was found to have been compiled without standard security hardening features in its MySQL backend component. This omission means that certain memory-related errors that would normally be caught and stopped by the system might instead lead to minor service disruptions. While the risk of a full system takeover is low, a remote attacker could potentially cause the file-sharing service to crash or become unavailable.
Technical details
The vulnerability stems from a protection mechanism failure (CWE-693) where the MySQL CNID source file explicitly disables FORTIFY_SOURCE during compilation. This removes runtime buffer overflow detection and hardening for that specific module. A remote attacker could potentially exploit memory errors that would otherwise be safely terminated by the compiler's runtime protection, leading to a minor denial of service (DoS). The issue is specific to the MySQL CNID backend and is considered to have low practical exploitability. Users are advised to upgrade to Netatalk 4.5.0 or apply the provided patch to version 4.4.2.
Affected products
- Netatalk Netatalk 3.1.2 through 4.4.2
Timeline
- 2026-05-13: disclosed
- 2026-05-21: advisory: NVD publication date