Home
LOW: 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
3.1.2 (semver)
affected
4.5.0 (semver)
unaffected
Description
Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would otherwise be caught and safely terminated by runtime protection.
Problem types
Product status
3.1.2 (semver)
4.5.0 (semver)
Credits
Arjun Basnet from Securin
References
netatalk.io/security/CVE-2026-44071 (Netatalk Security Advisory CVE-2026-44071)