CVE-2026-44075: Missing break in DSI OpenSession
A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPTATTNQUANT switch case to fall through into DSIOPTSERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI session options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44075?
The severity of CVE-2026-44075 is rated as low with a score of 3.7.
How does CVE-2026-44075 impact Netatalk?
CVE-2026-44075 affects Netatalk versions 1.5.0 through 4.4.2 by allowing unintended session option handling due to a missing break statement.
What versions of Netatalk are affected by CVE-2026-44075?
CVE-2026-44075 affects Netatalk versions 1.5.0 through 4.4.2.
How can I mitigate the effects of CVE-2026-44075?
Mitigation of CVE-2026-44075 can be achieved by updating to a patched version of Netatalk.
Is CVE-2026-44075 exploitable by remote attackers?
Yes, CVE-2026-44075 can be exploited by remote attackers to potentially cause minor service disruptions.