CVE-2026-44066

7.1

Netatalk · Netatalk

Multiple heap out-of-bounds reads exist in the Spotlight RPC unmarshalling code in Netatalk 3, potentially allowing information disclosure.

Executive summary

A heap out-of-bounds read vulnerability in Netatalk 3 allows authenticated attackers to potentially access sensitive memory.

Vulnerability

The vulnerability is an out-of-bounds read (CWE-125) within the Spotlight RPC unmarshalling code. Based on the CVSS vector (PR:L), this requires a low-privilege authenticated user to successfully trigger the flaw.

Business impact

Successful exploitation of this vulnerability could lead to the exposure of sensitive information residing in memory. While the CVSS score of 7.1 (High) reflects the potential for information disclosure and service impact, the requirement for authenticated access reduces the immediate risk to external-facing environments.

Remediation

Immediate Action: Update Netatalk to version 4.4.3 or later, where this vulnerability has been addressed.

Proactive Monitoring: Review system and application logs for unusual RPC traffic or unexpected process crashes that may indicate exploitation attempts.

Compensating Controls: Restrict access to Netatalk services to trusted users only and ensure network segmentation is in place to limit the reach of potential attackers.

Exploitation status

Public Exploit Available: No (unknown).

Analyst recommendation

Given the severity of this memory-handling flaw, administrators should prioritize updating to the patched version, 4.4.3. Ensuring that all Netatalk instances are running the latest software version is the most effective way to mitigate this risk.

More Netatalk CVEs