{"apiVersion":"1.0","identifier":"CVE-2026-45698","description":"Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the deletedir() function of Netatalk-s afpd daemon due to an integer underflow in the calculation of the remaining buffer size used for path construction. deletedir() is a utility function called when a file operation crosses a device boundary inside an AFP shared volume, which the standard library-s renameat() cannot handle. The function attempts to prevent buffer overflows by tracking available space in a size_t remain variable. However, the arithmetic used to compute remain results in an unsigned integer underflow, causing the variable to become SIZE_MAX. Because of this, the subsequent boundary check always evaluates as safe, allowing an unbounded strcpy() operation to copy attacker-controlled filenames into a nearly full stack buffer. Version 4.4.3 patches the issue.","publishedAt":"2026-08-17T19:16:30","lastModifiedAt":"2026-08-17T20:16:43","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45698","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00272,"riskScore":0.77,"affectedProduct":"Netatalk","affectedVersions":">=3.1.19,<4.4.3","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-45698","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-45698","en":"https://www.redsauce.net/en/cves/CVE-2026-45698","fr":"https://www.redsauce.net/fr/cves/CVE-2026-45698","pt":"https://www.redsauce.net/pt/cves/CVE-2026-45698","de":"https://www.redsauce.net/de/cves/CVE-2026-45698","sk":"https://www.redsauce.net/sk/cves/CVE-2026-45698","el":"https://www.redsauce.net/el/cves/CVE-2026-45698"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-45698"}}