What is CVE-2026-45699?
A stack-based buffer overflow vulnerability exists in the copydir() function of Netatalk's afpd daemon, affecting versions 3.1.19 through 4.4.2, caused by an integer underflow in the remaining buffer size calculation for path handling. This may allow remote code execution; applying the necessary patch on affected systems is strongly advised.
Azərbaycanca: Netatalk fayl server paketinin 3.1.19-dən 4.4.2 versiyalarına qədər olan aralığında, afpd demonunun copydir() funksiyasında tam ədəd alt daşması (integer underflow) səbəbindən stack-based buffer overflow zəifliyi mövcuddur. Bu, uzaqdan kod icrasına imkan yarada bilər; təsirə məruz qalan sistemlərdə dərhal müvafiq patchi tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What is the root cause of CVE-2026-45699 targeting Netatalk's copydir() function?
The vulnerability is an integer underflow in the calculation of the remaining buffer size for path handling within the copydir() function of the afpd daemon.
Which Netatalk versions are affected by CVE-2026-45699 and what is the risk?
The vulnerability affects Netatalk versions 3.1.19 through 4.4.2 and may allow remote code execution (RCE) due to the stack-based buffer overflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.