CVE-2024-38441: Netatalk

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions.

Affected products

  • Netatalk Netatalk: from 2.0.0, before 2.4.1 (fixed in 2.4.1); from 3.0, before 3.1.19 (fixed in 3.1.19); version 3.2.0 only

Published 2024-06-16. Last modified 2026-06-17.