Unrated severityNVD Advisory· Published Nov 12, 2022· Updated Feb 13, 2026
CVE-2022-45188
CVE-2022-45188
Description
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Affected products
1- Netatalk/Netatalkdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZYWSGVA6WXREMB6PV56HAHKU7R6KPOP/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GEAFLA5L2SHOUFBAGUXIF2TZLGBXGJKT/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SG6WZW5LXFVH3P7ZVZRGHUVJEMEFKQLI/mitrevendor-advisory
- security.gentoo.org/glsa/202311-02mitrevendor-advisory
- www.debian.org/security/2023/dsa-5503mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/05/msg00018.htmlmitremailing-list
- netatalk.sourceforge.io/3.1/ReleaseNotes3.1.13.htmlmitre
- netatalk.sourceforge.io/3.1/ReleaseNotes3.1.14.htmlmitre
- rushbnt.github.io/bug%20analysis/netatalk-0day/mitre
- sourceforge.net/projects/netatalk/files/netatalk/mitre
News mentions
1- ZDI-26-187: (Pwn2Own) Synology DiskStation Manager Netatalk Library Buffer Overflow Remote Code Execution VulnerabilityZero Day Initiative · Mar 16, 2026