Output Length Check Vulnerability in Netatalk Software
CVE-2026-44062
7.5HIGH
What is CVE-2026-44062?
A vulnerability exists in Netatalk versions 2.0.4 through 4.4.2 due to a missing output length bounds check in the 'pull_charset_flags()' function. This flaw permits a remote authenticated attacker to manipulate input data, potentially allowing for arbitrary code execution or a denial of service condition. Proper validation of character set data is critical to mitigating this risk.
Affected Version(s)
Netatalk 2.0.4 <= 4.4.2
Netatalk 4.4.3
