Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2026-44074

Bitwise OR of errno values_CVE-2026-44074

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occ...

Netatalk Netatalk 2.1.0 CVE
LOW 3.7 CVE-2026-44071

FORTIFY_SOURCE disabled_CVE-2026-44071

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing...

Netatalk Netatalk 3.1.2 CVE
LOW 3.1 CVE-2026-44057

Dead bounds check in Spotlight RPC unmarshaller_CVE-2026-44057

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effectiv...

Netatalk Netatalk 3.0.0 CVE
LOW 3.1 CVE-2026-7836

hextoint macro uppercase bug_CVE-2026-7836

In Netatalk 2.0.0 through 4.4.2, hextoint macro uppercase bug. Fixed in 4.5.0.

Netatalk Netatalk 2.0.0 CVE
LOW 3.1 CVE-2026-7835

Format string argument mismatch_CVE-2026-7835

In Netatalk 3.0.3 through 4.4.2, format string argument mismatch. Fixed in 4.5.0.

Netatalk Netatalk 3.0.3 CVE
LOW 2.5 CVE-2026-44072

system() after failed chdir()_CVE-2026-44072

In Netatalk 2.2.1 through 4.4.2, system() after failed chdir(). Fixed in 4.5.0.

Netatalk Netatalk 2.2.1 CVE
LOW 3.1 CVE-2026-44070

Unbounded realloc in charset conversion_CVE-2026-44070

In Netatalk 2.0.0 through 4.4.2, unbounded realloc in charset conversion. Fixed in 4.5.0.

Netatalk Netatalk 2.0.0 CVE
LOW 3.4 CVE-2026-44069

Integer underflow in volxlate_CVE-2026-44069

In Netatalk 3.0.0 through 4.4.2, integer underflow in volxlate. Fixed in 4.5.0.

Netatalk Netatalk 3.0.0 CVE
LOW 3.7 CVE-2026-44067

EA header parsing heap over-read_CVE-2026-44067

In Netatalk 2.1.0 through 4.4.2, ea header parsing heap over-read. Fixed in 4.5.0.

Netatalk Netatalk 2.1.0 CVE
LOW 3.7 CVE-2026-44065

Off-by-two in papd lp_write()_CVE-2026-44065

In Netatalk 2.0.0 through 4.4.2, off-by-two in papd lp_write(). Fixed in 4.5.0.

Netatalk Netatalk 2.0.0 CVE