Ubuntu alert USN-8395-1 (netatalk)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8395-1] Netatalk vulnerabilities | |
| Date: | Tue, 09 Jun 2026 06:47:51 +0000 | |
| Message-ID: | <E1wWqFb-0001hf-1A@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8395-1 June 08, 2026 netatalk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Netatalk. Software Description: - netatalk: Apple Filing Protocol service Details: Arjun Basnet discovered that Netatalk incorrectly sanitized user input in its MySQL CNID backend. A remote authenticated attacker could possibly use this issue to conduct SQL injection attacks. (CVE-2026-44047) Arjun Basnet discovered that Netatalk incorrectly handled UCS-2 character set conversion. A remote authenticated attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-44048) Arjun Basnet discovered that Netatalk improperly handled null termination during character set conversion. A remote authenticated attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-44049) Arjun Basnet discovered that the Netatalk CNID daemon improperly handled request-supplied name lengths. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code with escalated privileges. (CVE-2026-44050) Arjun Basnet discovered that Netatalk improperly resolved symbolic links. A remote authenticated attacker could possibly use this issue to read or overwrite arbitrary files on the system. (CVE-2026-44051) Arjun Basnet discovered that Netatalk incorrectly handled logging when performing LDAP simple-bind operations. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-44052) Arjun Basnet discovered that Netatalk contained an operator precedence logic error when processing input. A remote authenticated attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-44055) Arjun Basnet discovered that Netatalk incorrectly handled DSI write requests. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-44060) Arjun Basnet discovered that Netatalk incorrectly validated output lengths when converting character sets. A remote authenticated attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-44062) Arjun Basnet discovered that Netatalk incorrectly handled length validation when parsing certain session identifiers. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-44064) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS netatalk 4.2.3~ds-2.1ubuntu0.1 Ubuntu 24.04 LTS netatalk 3.1.18~ds-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS netatalk 3.1.12~ds-9ubuntu0.22.04.4+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS netatalk 3.1.12~ds-4ubuntu0.20.04.4+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS netatalk 2.2.6-1ubuntu0.18.04.2+esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS netatalk 2.2.5-1ubuntu0.2+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS netatalk 2.2.2-1ubuntu2.2+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8395-1 CVE-2026-44047, CVE-2026-44048, CVE-2026-44049, CVE-2026-44050, CVE-2026-44051, CVE-2026-44052, CVE-2026-44055, CVE-2026-44060, CVE-2026-44062, CVE-2026-44064 Package Information: https://launchpad.net/ubuntu/+source/netatalk/4.2.3~ds-2....
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmontjsACgkQcpJm3tlz hgF5WQ/9FWvi+IW1r9miB5YQi4AoKRFDbyqODJ4qs/rH6visIOFy+i6us/pCR+jV Gqsb0lj0wQzc9G4HBJIGq0JW1kgtMZpYwxZ5UsQZ+RW29urqHFLgql2s31oTMwbi yeUlcf1DUsLYwB0DCm0xaGbqk2caadO5Vg2b0tCy4JfJMjN3NUyxEmyYVuUtXihM L5Xmdi/47mv3FYDoCXJM2BGP5s/m8DYLnHLm/E6MiDZRD1a5HSqojjKG5lF/Q9i5 DQTaPjpl83i4Q/dvL8/7cYKJ02IVbzu2I5fRPZ6UzJCFJSSNo0/xNAnwyCSP85+e xF9WG793MNCM65dLtYrgt1xOQ9V0BIcGqrDoD4D7mgrz2LaHgwRFJ+FWBP7zihSM OUTxwrJf6BiQExVl77Aj/ybfsDOcjPJy1msp9Slmv7HASBR/icSMBEj/g89E5J3M InM+LJW2O+0au9imdWY5zlp63zHeHm0Yh0a537BP+U7gw6K3Al0KWEp8L/fMKO0Q ox67Xro2lhgVJ8bCNwned8y1h9oz6FrZKrqdBbzchf8IEkBU9SFt+h94uPWCPDUa zaPbKFpM5mIXqm4fCrTRQKLF19N/0IHWnk+xcI1DcFAaIgnZOp1AgNKmyOEAyEVh b1fDBB1oSVAS0e7iqenv/gU88byy2JUCB/Eo9KgRyWzI7cGOTaU= =tpBv -----END PGP SIGNATURE-----
