CVE-2026-44048: Stack buffer overflow via UCS-2 type confusion in convert_charset()
Published May 21, 2026
·Updated
A stack-based buffer overflow via UCS-2 type confusion in convertcharset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.
Affected Software
1 affected component
Netatalk Netatalk>=2.0.4<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44048?
CVE-2026-44048 has a high severity rating of 8.8 on the CVSS scale.
2
How does CVE-2026-44048 allow an attacker to execute arbitrary code?
CVE-2026-44048 allows a remote authenticated attacker to exploit a stack buffer overflow via UCS-2 type confusion in the convert_charset() function.
3
Which versions of Netatalk are affected by CVE-2026-44048?
CVE-2026-44048 affects Netatalk versions 2.0.4 through 4.4.2.
4
What type of vulnerability is represented by CVE-2026-44048?
CVE-2026-44048 represents a buffer overflow vulnerability that can lead to arbitrary code execution.
5
What should users do to mitigate the risk associated with CVE-2026-44048?
Users should upgrade to a patched version of Netatalk that resolves the vulnerability as per the software's security recommendations.