Type Confusion in Netatalk - CVE-2023-42464

 

Type Confusion in Netatalk - CVE-2023-42464

Published: September 18, 2023 / Updated: July 18, 2026


Vulnerability identifier: #VU80842
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-42464
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a type confusion error within the dalloc_value_for_key() function when parsing Spotlight RPC packets. A remote attacker can send specially crafted Spotlight RPC packets to the application, trigger a type confusion error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Netatalk
QNAP QTS
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12
Slackware Linux
Ubuntu
QuTS hero
libatalk12
netatalk
netatalk-devel
netatalk-debugsource
netatalk-debuginfo
libatalk12-debuginfo
netatalk (Ubuntu package)
netatalk (Debian package)

How to mitigate CVE-2023-42464

Install updates from vendor's website.

Netatalk - update to 3.1.17
QuTS hero - update to h5.2.5.3138 build 20250519
libatalk12 - update to 3.1.0-3.19.1
netatalk - update to 3.1.0-3.19.1
netatalk-devel - update to 3.1.0-3.19.1
netatalk-debugsource - update to 3.1.0-3.19.1
netatalk-debuginfo - update to 3.1.0-3.19.1
libatalk12-debuginfo - update to 3.1.0-3.19.1
netatalk (Ubuntu package) - addressed in versions 3.1.12~ds-4ubuntu0.20.04.3, 3.1.12~ds-9ubuntu0.22.04.3, 3.1.14~ds-1ubuntu0.1
netatalk (Debian package) - update to 3.1.12~ds-8+deb11u1
netatalk - update to 3.1.17
QNAP QTS - update to 5.2.5.3145 20250526

External References

Related Security Bulletins