Executive brief
Netatalk, a file server suite that allows Linux and Unix systems to serve files to Apple computers, contains a logic error in how it handles file permission errors. Under specific conditions where multiple errors occur at once, the system may process them incorrectly due to a mathematical error in the code. This could lead to minor service disruptions, though the developers consider the practical security risk to be very low.
Technical details
A logic error (CWE-682) exists in Netatalk's ACL error handling where errno values are combined using a bitwise OR operator. This results in incorrect error code mapping when multiple error conditions occur simultaneously. A remote attacker could potentially trigger these incorrect error-handling paths to cause a minor service disruption (Availability: Low). The vulnerability is difficult to exploit (Attack Complexity: High) as it requires specific simultaneous error conditions. The issue is addressed in Netatalk version 4.5.0 or via a provided source patch for version 4.4.2.
Affected products
- Netatalk Netatalk 2.1.0 through 4.4.2
Timeline
- 2026-05-13: disclosed: Initial disclosure date reported by vendor
- 2026-05-21: advisory: NVD publication date