PatchSiren cyber security CVE debrief
CVE-2026-44075 Netatalk CVE debrief
CVE-2026-44075 is a low-severity network-reachable session-handling flaw in Netatalk's DSI OpenSession path. A missing break statement allows the DSIOPT_ATTNQUANT case to fall through into DSIOPT_SERVQUANT, which can lead to unintended session option handling. The documented impact is limited to minor service disruption, but administrators should treat it as a real availability issue on exposed Netatalk deployments.
- Vendor
- Netatalk
- Product
- Unknown
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-05-21
Who should care
Administrators and operators running Netatalk services, especially systems that accept remote DSI session setup traffic. Network and storage teams should review exposure, because the issue is triggered remotely through crafted session options.
Technical summary
The flaw is a switch-case fallthrough in DSI OpenSession processing. When DSIOPT_ATTNQUANT is handled, execution can continue into DSIOPT_SERVQUANT because a break is missing. That can cause the service to process session options incorrectly and destabilize the session setup path. NVD lists the issue with CVSS 3.1 vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L and CWE-484 (Omitted Break Statement in Switch). The affected range in the source summary is Netatalk 1.5.0 through 4.4.2.
Defensive priority
Low
Recommended defensive actions
- Identify whether any exposed systems are running Netatalk versions 1.5.0 through 4.4.2.
- Review the linked Netatalk advisory for vendor guidance and upgrade guidance.
- Apply the vendor fix or move to a version newer than the affected range once validated against the advisory.
- Limit network exposure of Netatalk services to trusted hosts where practical.
- Monitor for unexpected DSI session errors, disconnects, or other signs of session setup instability.
Evidence notes
The NVD record for CVE-2026-44075 was published on 2026-05-21 and is marked Received. It cites a Netatalk security advisory URL and maps the issue to CWE-484 with CVSS 3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L. The supplied description states that a missing break in DSI OpenSession processing causes DSIOPT_ATTNQUANT to fall through into DSIOPT_SERVQUANT, allowing crafted session options to cause minor service disruption. Vendor attribution in the source metadata is marked low-confidence and needs review, so Netatalk should be treated as the referenced product/project from the advisory rather than as a fully confirmed vendor field.
Official resources
-
CVE-2026-44075 CVE record
CVE.org
-
CVE-2026-44075 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
33c584b5-0579-4c06-b2a0-8d8329fcab9c
Publicly disclosed in the CVE record and NVD on 2026-05-21, with NVD referencing the Netatalk advisory at netatalk.io/security/CVE-2026-44075.