Heap Over-read Vulnerability in Netatalk by Netatalk
CVE-2026-44067

3.7LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44067?

A vulnerability exists in the Netatalk software that allows an attacker, who has gained authenticated access, to exploit a flaw in the processing of extended attribute (EA) headers. This exploitation could enable the attacker to read unexpected portions of memory, potentially exposing limited sensitive information or causing minor disruptions to the service. The issue affects various versions of Netatalk, specifically from 2.1.0 to 4.4.2, and requires careful monitoring and mitigation to safeguard against potential exploits.

Affected Version(s)

Netatalk 2.1.0 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.