Junglewise Threat Intelligence

CVE-2026-44074: Netatalk incorrect calculation in ACL error handling

CVE-2026-44074 · Severity: low · CVSS 3.7 · Published 2026-05-21

Technologies: Netatalk. Vendors: Netatalk.

Executive brief

Netatalk, a file server suite that allows Linux and Unix systems to serve files to Apple computers, contains a logic error in how it handles file permission errors. Under specific conditions where multiple errors occur at once, the system may process them incorrectly due to a mathematical error in the code. This could lead to minor service disruptions, though the developers consider the practical security risk to be very low.

Technical details

A logic error (CWE-682) exists in Netatalk's ACL error handling where errno values are combined using a bitwise OR operator. This results in incorrect error code mapping when multiple error conditions occur simultaneously. A remote attacker could potentially trigger these incorrect error-handling paths to cause a minor service disruption (Availability: Low). The vulnerability is difficult to exploit (Attack Complexity: High) as it requires specific simultaneous error conditions. The issue is addressed in Netatalk version 4.5.0 or via a provided source patch for version 4.4.2.

Affected products

  • Netatalk Netatalk 2.1.0 through 4.4.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure date reported by vendor
  • 2026-05-21: advisory: NVD publication date

References

Related threats