A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://netatalk.io/security/CVE-2026-7837 |
|
History
Thu, 21 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netatalk
Netatalk netatalk |
|
| Vendors & Products |
Netatalk
Netatalk netatalk |
Thu, 21 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions. | |
| Title | TOCTOU with root privilege in ad_flush | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-05-21T08:23:46.648Z
Reserved: 2026-05-05T07:25:36.674Z
Link: CVE-2026-7837
No data.
Status : Received
Published: 2026-05-21T09:16:30.803
Modified: 2026-05-21T09:16:30.803
Link: CVE-2026-7837
No data.
OpenCVE Enrichment
Updated: 2026-05-21T10:30:08Z
Weaknesses