CVE-2026-44074 Details
Description
Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths.
A vulnerability exists in Netatalk versions 2.1.0 through 4.4.2, where the error handling for Access Control Lists (ACLs) incorrectly combines multiple error numbers using a bitwise OR operation. This mismanagement of error codes can lead to improper error handling when multiple issues arise simultaneously. As a result, a remote attacker might exploit this vulnerability to cause a minor disruption of service by triggering these incorrect error-handling pathways.
Users can apply the patch named 'CVE-2026-44074.patch' to a Netatalk 4.4.2 source tree to hotfix their local Netatalk deployment. Alternatively, upgrading to Netatalk version 4.5.0 or later, which includes the patch, is recommended. However, the Netatalk team advises against proactively applying the patch to existing deployments due to the low practical exploitability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2026CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://netatalk.io/security/CVE-2026-44074 | securin | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-682 | Incorrect Calculation | securin |
Affected Products
| Product | Versions |
|---|---|
| Netatalk | >= 2.1.0, <= 4.4.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | securin |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | New CVE Received | securin |
Volerion