CVE-2026-44050: Heap buffer overflow in CNID daemon comm_rcv()
Published May 21, 2026
·Updated
A heap-based buffer overflow in the CNID daemon commrcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.
Affected Software
1 affected component
Netatalk Netatalk cnid daemon>=2.0.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44050?
CVE-2026-44050 has a critical severity score of 9.9.
2
How do I fix CVE-2026-44050?
To mitigate CVE-2026-44050, update Netatalk to version 4.4.3 or later, which includes the necessary patches.
3
What type of attack is enabled by CVE-2026-44050?
CVE-2026-44050 allows remote authenticated attackers to execute arbitrary code or cause a denial of service.
4
Which versions of Netatalk are affected by CVE-2026-44050?
Netatalk versions 2.0.0 through 4.4.2 are affected by CVE-2026-44050.
5
What kind of vulnerability is CVE-2026-44050 classified as?
CVE-2026-44050 is classified as a heap buffer overflow vulnerability.