What is CVE-2026-45698?
A stack-based buffer overflow vulnerability was discovered in the deletedir() function of Netatalk's afpd daemon, affecting versions 3.1.19 through 4.4.2. This is caused by an integer underflow in the remaining buffer size calculation for path handling. It is recommended to update Netatalk to a secure version.
Azərbaycanca: Netatalk fayl server paketinin 3.1.19-dan 4.4.2-dək versiyalarında afpd demonunun deletedir() funksiyasında stack-based buffer overflow zəifliyi aşkarlanıb. Bu, bufer ölçüsünün hesablanmasında integer underflow səbəbindən baş verir. Təsirə məruz qalan sistemlərdə Netatalk-ı təhlükəsiz versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which versions of Netatalk are affected by CVE-2026-45698?
The vulnerability affects Netatalk versions 3.1.19 through 4.4.2.
What is the root cause of CVE-2026-45698?
The vulnerability is a stack-based buffer overflow in the deletedir() function of the afpd daemon, caused by an integer underflow in the remaining buffer size calculation for path handling.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.