CVE-2026-44053

Publication date 21 May 2026

Last updated 9 June 2026


Ubuntu priority

Cvss 3 Severity Score

7.4 · High

Score breakdown

Description

Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic attack.

Read the notes from the security team

Status

Package Ubuntu Release Status
netatalk 26.04 LTS resolute Ignored
25.10 questing Ignored
24.04 LTS noble Ignored
22.04 LTS jammy Ignored
20.04 LTS focal Ignored
18.04 LTS bionic Ignored
14.04 LTS trusty Ignored

Notes


shishirsub10

The Netatalk team does not encourage proactively applying the patch to existing deployments because of the low practical exploitability.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
netatalk

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.4 · High

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N


Access our resources on patching vulnerabilities