CVE-2026-45698Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction. deletedir() is a utility function called when a file operation crosses a device boundary inside an AFP shared volume, which the standard library's renameat() cannot handle. The function attempts to prevent buffer overflows by tracking available space in a size_t remain variable. However, the arithmetic used to compute remain results in an unsigned integer underflow, causing the variable to become SIZE_MAX. Because of this, the subsequent boundary check always evaluates as safe, allowing an unbounded strcpy() operation to copy attacker-controlled filenames into a nearly full stack buffer. Version 4.4.3 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-17: 3Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 208-17
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-45698](https://github.com/Netatalk/netatalk/releases/tag/netatalk-4-4-3) Netatalk is a ... https://github.com/Netatalk/netatalk/releases/tag/netatalk-4-4-3 #Vulnerability #CVE #ZeroDay

    Post summary

    Tweet announces CVE-2026-45698 in Netatalk and links to the 4.4.3 release, implying a patch, but lacks exploit details or technical specifics.

    0000024
    27 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-45698 Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the de… https://www.cve.org/CVERecord?id=CVE-2026-45698 ----- Traducción: CVE-2026-45698 Net… https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-45698, detailing a stack-based buffer overflow in Netatalk, but offers no proof of concept, exploitation tool, active exploitation evidence, or patch information.

    0000022
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45698 Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the de… https://www.cve.org/CVERecord?id=CVE-2026-45698

    Post summary

    The statement announces a stack‑based buffer overflow vulnerability (CVE‑2026‑45698) found in Netatalk versions 3.1.19–4.4.2, with no mention of PoC, exploit code, active attacks, or patches.

    00000766
    58.0K followersView on X

Explore more