CVE-2026-44064
7.1Netatalk · Netatalk
An out-of-bounds read vulnerability exists in the ASP session ID handling logic of Netatalk 1, potentially leading to service disruption or information disclosure.
Executive summary
An out-of-bounds read vulnerability in Netatalk 1 session handling poses a risk of service interruption and information disclosure to adjacent network attackers.
Vulnerability
This is an out-of-bounds read (CWE-125) triggered during the handling of ASP session IDs. The CVSS vector (AV:A) indicates that the attacker must be positioned on the adjacent network to exploit this flaw.
Business impact
The vulnerability carries a CVSS score of 7.1 (High), primarily due to its potential to cause a denial-of-service condition (impacting availability) or unauthorized information exposure. Organizations relying on Netatalk for file sharing services may face operational downtime if the service is crashed via this vector.
Remediation
Immediate Action: Update the Netatalk installation to version 4.4.3 or later to resolve the session handling flaw.
Proactive Monitoring: Monitor network-level traffic for anomalous packets directed at the Netatalk service, specifically targeting session ID parameters.
Compensating Controls: Implement network access controls to ensure only authorized devices can communicate with the Netatalk service, mitigating the adjacent network attack vector.
Exploitation status
Public Exploit Available: No (unknown).
Analyst recommendation
The vulnerability necessitates a patch to the latest version (4.4.3) to ensure service stability and security. Administrators should schedule these updates during the next maintenance window to minimize potential exposure.