GHSA-8qf9-m7wh-563jLowCVSS 3.7

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a...

Published
May 21, 2026
Last Modified
May 21, 2026

🔗 CVE IDs covered (1)

📋 Description

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI session options.

🔗 References (3)