Integer overflow in Netatalk - #VU147250

 

Integer overflow in Netatalk - #VU147250

Published: September 7, 2026


Vulnerability identifier: #VU147250
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass AppleDouble entry-length validation.

The vulnerability exists due to integer overflow in parse_entries() in libatalk/adouble/ad_open.c when parsing crafted AppleDouble headers. A remote attacker can place a crafted file, macOS ._ AppleDouble sidecar, or org.netatalk.Metadata extended attribute on a shared volume that afpd later parses to bypass AppleDouble entry-length validation.

Audited consumers perform additional validation, and no confidentiality, integrity, or availability impact has been substantiated from this defect alone.


Affected software

Netatalk

Remediation

Install security update from vendor's website.

Netatalk - update to 4.6.0

External References

Related Security Bulletins