PatchSiren cyber security CVE debrief
CVE-2026-44075 Netatalk CVE debrief
CVE-2026-44075 is a low-severity network-reachable session-handling flaw in Netatalk's DSI OpenSession path. A missing break statement allows the DSIOPT_ATTNQUANT case to fall through into DSIOPT_SERVQUANT, which can lead to unintended session option handling. The documented impact is limited to minor service disruption, but administrators should treat it as a real availability issue on exposed Netatalk deployments.
- Vendor
- Netatalk
- Product
- Unknown
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-07-23
Who should care
Administrators and operators running Netatalk services, especially systems that accept remote DSI session setup traffic. Network and storage teams should review exposure, because the issue is triggered remotely through crafted session options.
Technical summary
The flaw is a switch-case fallthrough in DSI OpenSession processing. When DSIOPT_ATTNQUANT is handled, execution can continue into DSIOPT_SERVQUANT because a break is missing. That can cause the service to process session options incorrectly and destabilize the session setup path. NVD lists the issue with CVSS 3.1 vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L and CWE-484 (Omitted Break Statement in Switch). The affected range in the source summary is Netatalk 1.5.0 through 4.4.2.
Defensive priority
Low
Recommended defensive actions
- Identify whether any exposed systems are running Netatalk versions 1.5.0 through 4.4.2.
- Review the linked Netatalk advisory for vendor guidance and upgrade guidance.
- Apply the vendor fix or move to a version newer than the affected range once validated against the advisory.
- Limit network exposure of Netatalk services to trusted hosts where practical.
- Monitor for unexpected DSI session errors, disconnects, or other signs of session setup instability.
Evidence notes
The NVD record for CVE-2026-44075 was published on 2026-05-21 and is marked Received. It cites a Netatalk security advisory URL and maps the issue to CWE-484 with CVSS 3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L. The supplied description states that a missing break in DSI OpenSession processing causes DSIOPT_ATTNQUANT to fall through into DSIOPT_SERVQUANT, allowing crafted session options to cause minor service disruption. Vendor attribution in the source metadata is marked low-confidence and needs review, so Netatalk should be treated as the referenced product/project from the advisory rather than as a fully confirmed vendor field.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44075 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44075
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44075 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44075
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://netatalk.io/security/CVE-2026-44075
33c584b5-0579-4c06-b2a0-8d8329fcab9c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.