Output Length Check Vulnerability in Netatalk Software
CVE-2026-44062

7.5HIGH

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44062?

A vulnerability exists in Netatalk versions 2.0.4 through 4.4.2 due to a missing output length bounds check in the 'pull_charset_flags()' function. This flaw permits a remote authenticated attacker to manipulate input data, potentially allowing for arbitrary code execution or a denial of service condition. Proper validation of character set data is critical to mitigating this risk.

Affected Version(s)

Netatalk 2.0.4 <= 4.4.2

Netatalk 4.4.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.