CVE-2026-49390
Public on 2026-06-01
Modified on 2026-06-01
Description
From https://netatalk.io/security/CVE-2026-49390, The server quantum option in afp.conf is not range-validated during configuration parsing. Although the manual states that out-of-range values fall back to the default, the parser can accept invalid values and pass them into afpd startup.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | talk | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |