CVE-2026-44065: Off-by-two in papd lp_write()
Published May 21, 2026
·Updated
An off-by-two error in lpwrite() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify limited data or cause a minor service disruption via crafted print data.
Affected Software
1 affected component
Netatalk Netatalk>=2.0.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44065?
The CVE-2026-44065 vulnerability has a medium severity rating of 4.2.
2
What causes CVE-2026-44065?
CVE-2026-44065 is caused by an off-by-two error in the lp_write() function of papd in Netatalk.
3
How do I fix CVE-2026-44065?
To fix CVE-2026-44065, upgrade Netatalk to version 4.5.0 or later.
4
What are the potential impacts of CVE-2026-44065?
CVE-2026-44065 can allow an adjacent network attacker to modify limited data or cause a minor service disruption.
5
Which versions of Netatalk are affected by CVE-2026-44065?
Netatalk versions 2.0.0 through 4.4.2 are affected by CVE-2026-44065.