CVE-2026-7837: TOCTOU with root privilege in ad_flush
Published May 21, 2026
·Updated
A time-of-check time-of-use (TOCTOU) condition in the adflush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions.
Affected Software
1 affected component
Netatalk Netatalk>=3.0.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·08:14 AM
Data Sourced
via MITRE·08:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Jun 23, 58372
Event
via FIRST·09:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-7837?
The severity of CVE-2026-7837 is rated as low with a score of 3.7.
2
How do I fix CVE-2026-7837?
To fix CVE-2026-7837, upgrade to a patched version of Netatalk that addresses the TOCTOU condition.
3
What software is affected by CVE-2026-7837?
CVE-2026-7837 affects Netatalk versions from 3.0.0 through 4.4.2.
4
What type of vulnerability is CVE-2026-7837?
CVE-2026-7837 is classified as a race condition vulnerability.
5
What can an attacker do with CVE-2026-7837?
An attacker could cause limited data modification under specific race conditions due to the TOCTOU issue.