Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol (AFP) used to share files with Apple computers. A flaw in the database cleanup process could allow a highly privileged local user to cause the system to delete or modify files in the wrong directory if they can force a directory change to fail. The risk is considered low as it requires significant local access and specific environmental conditions to exploit.
Technical details
A vulnerability exists in the CNID (Catalog Node ID) database cleanup routine where the application continues to execute a shell command via system() even after a chdir() call fails. While the command itself is fixed and does not allow for arbitrary command injection, the failure to verify the working directory means the cleanup command may execute against files in an unintended location. Exploitation requires local access with high privileges (PR:H) and a high degree of complexity (AC:H) to manipulate the environment such that the directory change fails while the subsequent command still executes. This issue is resolved in Netatalk version 4.5.0.
Affected products
- Netatalk Netatalk 2.2.1 through 4.4.2
Timeline
- 2026-05-13: disclosed: Initial disclosure date
- 2026-05-21: advisory: NVD publication date
- 2026-05-21: patched: Fixed in version 4.5.0