CVE-2026-44067: EA header parsing heap over-read
Published May 21, 2026
·Updated
A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to obtain limited information or cause a minor service disruption via crafted EA data.
Affected Software
1 affected component
Netatalk Netatalk>=2.1.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44067?
The severity of CVE-2026-44067 is low, rated at 3.7.
2
How can I mitigate CVE-2026-44067?
To mitigate CVE-2026-44067, upgrade to Netatalk version 4.5.0 or later.
3
What does CVE-2026-44067 affect?
CVE-2026-44067 affects versions of Netatalk from 2.1.0 through 4.4.2.
4
What type of vulnerability is CVE-2026-44067?
CVE-2026-44067 is a heap over-read vulnerability during EA header parsing.
5
Is user interaction required for CVE-2026-44067?
No, user interaction is not required to exploit CVE-2026-44067.