Off-by-Two Vulnerability in Netatalk Affects Network Printing
CVE-2026-44065

3.7LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44065?

A vulnerability in the lp_write() function of the papd service in Netatalk versions 2.0.0 through 4.4.2 can be exploited by an adjacent network attacker. By sending specially crafted print data, the attacker may modify limited data or induce a minor service disruption. This highlights the importance of securing network printing services against unauthorized access and carefully validating input data to prevent potential disruptions.

Affected Version(s)

Netatalk 2.0.0 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.