Heap-based buffer overflow in Netatalk - CVE-2022-43634

 

Heap-based buffer overflow in Netatalk - CVE-2022-43634

Published: February 13, 2023 / Updated: July 18, 2026


Vulnerability identifier: #VU72143
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-43634
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the dsi_writeinit() function in libatalk/dsi/dsi_write.c. A remote attacker can send specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Netatalk
QNAP QTS
Debian Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
Slackware Linux
Ubuntu
Fedora
netatalk (Ubuntu package)
libatalk12-debuginfo
netatalk-devel
netatalk-debugsource
netatalk-debuginfo
netatalk
libatalk12
netatalk (Debian package)
QuTS hero

How to mitigate CVE-2022-43634

Install updates from vendor's website.

Netatalk - addressed in versions 2.2.7, 3.1.14
netatalk (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.12~ds-4ubuntu0.20.04.1, 3.1.12~ds-9ubuntu0.22.04.1, 3.1.13~ds-2ubuntu0.22.10.1
QuTS hero - update to h5.1.3.2578 build 20231110
libatalk12-debuginfo - update to 3.1.0-3.14.1
netatalk-devel - update to 3.1.0-3.14.1
netatalk-debugsource - update to 3.1.0-3.14.1
netatalk-debuginfo - update to 3.1.0-3.14.1
netatalk - update to 3.1.0-3.14.1
libatalk12 - update to 3.1.0-3.14.1
netatalk - addressed in versions 3.1.12, 3.1.15
netatalk (Debian package) - update to 3.1.12~ds-8+deb11u1
netatalk - addressed in versions 3.1.14-3.fc36, 3.1.14-3.fc37, 3.1.14-3.fc38
QNAP QTS - update to 5.1.3.2578 20231110

External References

Related Security Bulletins