CVE-2026-44066: Heap out-of-bounds reads in Spotlight RPC unmarshalling
Published May 21, 2026
·Updated
Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor service disruption.
Affected Software
1 affected component
Netatalk Netatalk>=3.1.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44066?
The severity of CVE-2026-44066 is high with a score of 7.1.
2
How do I fix CVE-2026-44066?
To fix CVE-2026-44066, upgrade Netatalk to version 4.4.3 or later.
3
What does CVE-2026-44066 affect?
CVE-2026-44066 affects Netatalk versions 3.1.0 through 4.4.2.
4
What type of vulnerability is CVE-2026-44066?
CVE-2026-44066 is a heap out-of-bounds read vulnerability.
5
What are the potential impacts of CVE-2026-44066?
The potential impacts of CVE-2026-44066 include unauthorized data access due to high confidentiality exposure.