Executive brief
Netatalk is an open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like systems to serve files to macOS clients. A minor software bug exists where a specific error message is incorrectly formatted, which could lead to a service crash under extremely rare low-memory conditions. Because this occurs only during a system-level memory failure, the risk to business operations and data security is considered very low.
Technical details
A format string argument mismatch (CWE-134) exists in Netatalk versions 3.0.3 through 4.4.2 within a logging statement located on an allocation-failure code path. The vulnerability occurs when a log message expects a string argument that is not provided by the calling function. Because the format string itself is static and not controlled by an attacker, the issue is not exploitable for arbitrary code execution. The impact is limited to a potential application crash (Denial of Service) if the system encounters an out-of-memory state that triggers the specific logging path. The issue is resolved in version 4.5.0.
Affected products
- Netatalk Project Netatalk 3.0.3 through 4.4.2
Timeline
- 2026-05-13: disclosed: Initial disclosure date
- 2026-05-21: advisory: NVD publication date