There are 11 open security issues in trixie.
11 issues left for the package maintainer to handle:
- CVE-2026-44053:
(needs triaging)
Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic attack.
- CVE-2026-44056:
(needs triaging)
A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.2 allows a remote authenticated attacker to cause a denial of service, obtain limited information, or modify limited data.
- CVE-2026-44058:
(needs triaging)
An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.
- CVE-2026-44061:
(needs triaging)
Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover authentication credentials via timing analysis.
- CVE-2026-44063:
(needs triaging)
An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDAP queries and obtain limited information or modify LDAP entries via crafted filter input.
- CVE-2026-44065:
(needs triaging)
An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify limited data or cause a minor service disruption via crafted print data.
- CVE-2026-44067:
(needs triaging)
A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to obtain limited information or cause a minor service disruption via crafted EA data.
- CVE-2026-49387:
(needs triaging)
- CVE-2026-49388:
(needs triaging)
- CVE-2026-49389:
(needs triaging)
- CVE-2026-49390:
(needs triaging)
You can find information about how to handle these issues in the security team's documentation.