Heap-based buffer overflow in Netatalk - CVE-2022-45188

 

Heap-based buffer overflow in Netatalk - CVE-2022-45188

Published: December 29, 2022 / Updated: July 18, 2026


Vulnerability identifier: #VU70538
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45188
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in afp_getappl when handling .appl files. A remote attacker can create a specially crafted .appl file, trick the victim into opening it, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Netatalk
QNAP QTS
Gentoo Linux
Debian Linux
Fedora
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Workstation Extension
Slackware Linux
Ubuntu
netatalk (Ubuntu package)
libatalk12-debuginfo
netatalk-devel
netatalk-debuginfo
libatalk12
netatalk
netatalk-debugsource
netatalk (Debian package)
net-fs/netatalk
QuTS hero

How to mitigate CVE-2022-45188

Install update from vendor's website.

Netatalk - addressed in versions 2.2.7, 3.1.14
netatalk (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.12~ds-4ubuntu0.20.04.1, 3.1.12~ds-9ubuntu0.22.04.1, 3.1.13~ds-2ubuntu0.22.10.1
QuTS hero - update to h5.2.5.3138 build 20250519
libatalk12-debuginfo - update to 3.1.0-3.11.1
netatalk-devel - update to 3.1.0-3.11.1
netatalk-debuginfo - update to 3.1.0-3.11.1
libatalk12 - update to 3.1.0-3.11.1
netatalk - update to 3.1.0-3.11.1
netatalk-debugsource - update to 3.1.0-3.11.1
netatalk - addressed in versions 3.1.12, 3.1.14, 3.1.15
netatalk (Debian package) - update to 3.1.12~ds-8+deb11u1
netatalk - addressed in versions 3.1.14-3.el7, 3.1.14-3.el8, 3.1.14-3.el9, 3.1.14-3.fc36, 3.1.14-3.fc37, 3.1.14-3.fc38
net-fs/netatalk - update to 3.1.18
QNAP QTS - update to 5.2.5.3145 20250526

External References

Related Security Bulletins