Heap-based buffer overflow in Netatalk - CVE-2022-45188
Published: December 29, 2022 / Updated: July 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in afp_getappl when handling .appl files. A remote attacker can create a specially crafted .appl file, trick the victim into opening it, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
QNAP QTS
Gentoo Linux
Debian Linux
Fedora
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Slackware Linux
Ubuntu
netatalk (Ubuntu package)
libatalk12-debuginfo
netatalk-devel
netatalk-debuginfo
libatalk12
netatalk
netatalk-debugsource
netatalk (Debian package)
net-fs/netatalk
QuTS hero
How to mitigate CVE-2022-45188
netatalk (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.12~ds-4ubuntu0.20.04.1, 3.1.12~ds-9ubuntu0.22.04.1, 3.1.13~ds-2ubuntu0.22.10.1
QuTS hero - update to h5.2.5.3138 build 20250519
libatalk12-debuginfo - update to 3.1.0-3.11.1
netatalk-devel - update to 3.1.0-3.11.1
netatalk-debuginfo - update to 3.1.0-3.11.1
libatalk12 - update to 3.1.0-3.11.1
netatalk - update to 3.1.0-3.11.1
netatalk-debugsource - update to 3.1.0-3.11.1
netatalk - addressed in versions 3.1.12, 3.1.14, 3.1.15
netatalk (Debian package) - update to 3.1.12~ds-8+deb11u1
netatalk - addressed in versions 3.1.14-3.el7, 3.1.14-3.el8, 3.1.14-3.el9, 3.1.14-3.fc36, 3.1.14-3.fc37, 3.1.14-3.fc38
net-fs/netatalk - update to 3.1.18
QNAP QTS - update to 5.2.5.3145 20250526
External References
Related Security Bulletins
- Remote code execution in Netatalk
- SUSE update for netatalk
- Slackware Linux update for netatalk
- Slackware Linux update for netatalk
- Ubuntu update for netatalk
- Fedora 38 update for netatalk
- Fedora 37 update for netatalk
- Fedora 36 update for netatalk
- Fedora EPEL 9 update for netatalk
- Fedora EPEL 8 update for netatalk
- Fedora EPEL 7 update for netatalk
- Debian update for netatalk
- Gentoo update for Netatalk
- Multiple vulnerabilities in QNAP QTS and QuTS hero