[From nobody Tue May 19 23:05:07 2026
Received: (at submit) by bugs.debian.org; 19 May 2026 19:49:37 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-24.5 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,BODY_INCLUDES_SEVERITY,DKIM_SIGNED,DKIM_VALID,
 DKIM_VALID_AU,DKIM_VALID_EF,HAS_PACKAGE,HTML_MESSAGE,PGPSIGNATURE,
 RCVD_IN_DNSWL_LOW,SPF_HELO_PASS,SPF_PASS autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 14; hammy, 93; neutral, 18; spammy, 1.
 spammytokens:0.941-+--H*r:bugs.debian.org
 hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc,
 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug, 0.000-+--H*Ad:N*Tracking
Return-path: &lt;daniel@mindani.net&gt;
Received: from mail-4327.protonmail.ch ([185.70.43.27]:10313)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;daniel@mindani.net&gt;) id 1wPQRd-008UC0-2F
 for submit@bugs.debian.org; Tue, 19 May 2026 19:49:37 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mindani.net;
 s=protonmail3; t=1779220163; x=1779479363;
 bh=C121i9FWU7GDX+XUy+0qENCvbFU70pTNm44fK+I5mkc=;
 h=Date:To:From:Subject:Message-ID:Feedback-ID:From:To:Cc:Date:
 Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector;
 b=ozxFJcOAM8zVqvlxFvEgWq1hRjoZoXfWsrucfKM4EvB2KcOs39l6UUhilF6ushK10
 +oobaUnlQllyLaQ+jFXM7vZ4wokTzgX1zvbNMhSchcwjP+QKhE98A9rxNTD5gnDMKX
 xc2L0XGSS1ALRSd8LvGplbZLhF+eB7PTMKsQg0VB04CQuyBfx1Ugjpdy7NCYY1m3wl
 WUHMZla90vnofQ+Z1/pbdWOVOH+kO+sosd3wfFbzNpLyURoDRyXWqW9DvGRAQ8NpHf
 TAmCeaqM0NjJFEm6FY6VsPZTeXXKibZ+QrYfBUl3ulSOJLASKJhtxaqHUFTchFJoPx
 Ao+0cjlHLtYyA==
Date: Tue, 19 May 2026 19:49:18 +0000
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
From: Daniel Markstedt &lt;daniel@mindani.net&gt;
Subject: CVE-2026-44048: Stack buffer overflow via UCS-2 type confusion in
 convert_charset()
Message-ID: &lt;50XhmzG157hdc7cbzkPFwSvMU8TdopzX1tKWYZNIEmgCVWG5csSxnU0FACflwvEoFIyqxf5KiF3hjkY0Is66DoOAD9SIWopRTQqvovZmUNM=@mindani.net&gt;
Feedback-ID: 84350481:user:proton
X-Pm-Message-ID: 680a9ca98a87ebce62f3e8b9d190a20a468bd143
MIME-Version: 1.0
Content-Type: multipart/signed; protocol=&quot;application/pgp-signature&quot;;
 micalg=pgp-sha512;
 boundary=&quot;------3133b41c750955d357ea6884972dacdd72aa44d775ae6045761ce04775cf1d13&quot;;
 charset=utf-8
Delivered-To: submit@bugs.debian.org

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------3133b41c750955d357ea6884972dacdd72aa44d775ae6045761ce04775cf1d13
Content-Type: multipart/mixed;boundary=---------------------3f8404d2afac3da29912430a63c7aebc

-----------------------3f8404d2afac3da29912430a63c7aebc
Content-Type: multipart/alternative;boundary=---------------------6ee5d593f955b2f80bcd6a5136d84121

-----------------------6ee5d593f955b2f80bcd6a5136d84121
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;charset=utf-8

Package: netatalkVersion: 4.4.2~ds-1
Severity: critical
X-Debbugs-Cc: pkg-netatalk-devel@lists.alioth.debian.org

will be resolved by upgrading to upstream v4.4.3
-----------------------6ee5d593f955b2f80bcd6a5136d84121
Content-Type: multipart/related;boundary=---------------------f994138278f35920d80c5b7c9ccc628c

-----------------------f994138278f35920d80c5b7c9ccc628c
Content-Type: text/html;charset=utf-8
Content-Transfer-Encoding: base64

PGRpdiBzdHlsZT0iZm9udC1mYW1pbHk6IEFyaWFsLCBzYW5zLXNlcmlmOyBmb250LXNpemU6IDE0
cHg7Ij48c3Bhbj5QYWNrYWdlOiBuZXRhdGFsazwvc3Bhbj48ZGl2PjxzcGFuPlZlcnNpb246IDQu
NC4yfmRzLTE8L3NwYW4+PC9kaXY+PGRpdj48c3Bhbj5TZXZlcml0eTogY3JpdGljYWw8L3NwYW4+
PC9kaXY+PGRpdj48c3Bhbj5YLURlYmJ1Z3MtQ2M6IDxhIHRhcmdldD0iX2JsYW5rIiByZWw9Im5v
cmVmZXJyZXIgbm9mb2xsb3cgbm9vcGVuZXIiIGhyZWY9Im1haWx0bzpwa2ctbmV0YXRhbGstZGV2
ZWxAbGlzdHMuYWxpb3RoLmRlYmlhbi5vcmciPnBrZy1uZXRhdGFsay1kZXZlbEBsaXN0cy5hbGlv
dGguZGViaWFuLm9yZzwvYT48L3NwYW4+PC9kaXY+PGRpdj48YnI+PC9kaXY+PGRpdj48c3Bhbj53
aWxsIGJlIHJlc29sdmVkIGJ5IHVwZ3JhZGluZyB0byB1cHN0cmVhbSB2NC40LjM8L3NwYW4+PC9k
aXY+PHNwYW4+PC9zcGFuPjxicj48L2Rpdj4KPGRpdiBzdHlsZT0iZm9udC1mYW1pbHk6IEFyaWFs
LCBzYW5zLXNlcmlmOyBmb250LXNpemU6IDE0cHg7IiBjbGFzcz0icHJvdG9ubWFpbF9zaWduYXR1
cmVfYmxvY2sgcHJvdG9ubWFpbF9zaWduYXR1cmVfYmxvY2stZW1wdHkiPgogICAgPGRpdiBjbGFz
cz0icHJvdG9ubWFpbF9zaWduYXR1cmVfYmxvY2stdXNlciBwcm90b25tYWlsX3NpZ25hdHVyZV9i
bG9jay1lbXB0eSI+CiAgICAgICAgCiAgICAgICAgICAgIDwvZGl2PgogICAgCiAgICAgICAgICAg
IDxkaXYgY2xhc3M9InByb3Rvbm1haWxfc2lnbmF0dXJlX2Jsb2NrLXByb3RvbiBwcm90b25tYWls
X3NpZ25hdHVyZV9ibG9jay1lbXB0eSI+CiAgICAgICAgCiAgICAgICAgICAgIDwvZGl2Pgo8L2Rp
dj4K
-----------------------f994138278f35920d80c5b7c9ccc628c--

-----------------------6ee5d593f955b2f80bcd6a5136d84121--

-----------------------3f8404d2afac3da29912430a63c7aebc
Content-Type: application/pgp-keys; filename=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;; name=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;; name=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;

LS0tLS1CRUdJTiBQR1AgUFVCTElDIEtFWSBCTE9DSy0tLS0tCgp4c0ZOQkdUeVVBZ0JFQURDRUY2
ZHBEa3VVaGlhd21mbXVxN0tMdmhrelozM1ZPSEMwbW9LaU1ON3lpUTYKaXR1QW5mblNLUWZTVkdY
TjUvTTd5ZTQvNDIvc3dKeWRxQlNGOHMrV1k4bHpIZ0VmZk1hK2NnRitkVS9BCktjOGZVTjA2NWFT
MlJIY1h4QXBBUFp3a0c5OFdmRnBFMjVhbFNLNm1EYk82T2dCRk8zME5USmpVQlNjOAp4b1duRmp4
dmQvSk15MDVXNVJmYk56eHgzaGxYaWI5NHNnK3JzWEdVaGt5bjdxR1k4Z0paT3YydXYzaTIKc2FM
MHRpdU5OVGVxRmVydzRnN05CSzhtSzArNkNWcG01Snh4L005MGRsQmQvaGRteVRBWUhGcjlTREh0
CmtmUW1EMVZLSlIyQkx1OWhmc3JwWGlUUDdmekQ1N0JFUzZ2VjREbTZkczg0SXJBTWdPeG5SSUho
aTFtWAo2OGJnWGhEUGNWM2JIeHVLWm4wM3pWMndlYnFzaWZuOXU2elRGQnc0SmxlY2lUSHBSYTd1
anh3cy9NbzMKN3liNEpqdDNZSmd5ZE1za0ErOEZHZ09scVhpVWEwdDhrWUdIQVRTTDhJWTNFVTFJ
TnVxdlFYbWo0V0VLCit6MDVXaWp4N0hFWFdZV0VrRGlGQkQ1RlhvWWNMNHZDUlNyczR0SDl4dmV2
VERaMXdLV0RxUW1oeW94Ngo0V0p1cUdkVUpRSGNQVDA2Slk2am9FNHlFN1NjdDJJZjBoZXVtVk5v
TDh5eVNRUFFwL0N5cU9NOHp0UG0KMGJ2eHN2RjhiM0xtemFGYjkzT0RvYjd6UzB2c25HdHlqbzgv
Sm0vb1hmb3pDNG5IZ3ZqV09NRUd6VHBMCjlVRkRBSjJSRnVONUU5c2F6SGZGL3gxN2NScVptWjYv
ekx1YWFRQVJBUUFCelNWRVlXNXBaV3dnVFdGeQphM04wWldSMElEeGtZVzVwWld4QWJXbHVaR0Z1
YVM1dVpYUSt3c0dPQkJNQkNnQTRBaHNEQlFzSkNBY0MKQmhVS0NRZ0xBZ1FXQWdNQkFoNEJBaGVB
RmlFRVBFZGtMa2R1R3hlbGEzb1JJelZaS2gveHR0b0ZBbWF3CklMUUFDZ2tRSXpWWktoL3h0dG80
N3cvL1N6SEJzeDZBWlIyZzJVcFpxYXljRThGK0h4OW95YnR6ZTROWApLeHp3VFBVeER6WEFpcFFS
czBsUlBpeHpCUFQ2d005TlN4Q2lIQTJyMFhvamRVc2lPWDcxclFURzhEbnAKdkpxcW1sSnpHN1l3
QmpKVWFaQjh4MkNacjV4T1MzQjU2MHluWTdxaWZzRDM5TUdtamZzZTV4VGloYU5pCk80YzF1TmhZ
eHhVMURTS0pGWExhSzZWTXVtYytMQmw4bkErbHZZU2lSd1BrMmwvQ3g3bVdjZk1nR05PQQpDdEJr
YnpnVndNZFAvcVBwQkV2cytpRWtyNUpmVkk2aytIM29OZmd1Y0t5K0U1UWFoOEhzNEZQYTg2U3AK
QXRZdnNwSGF4NG8zWnJ2UVRyeTBSaG9XbkFlSTN5VUlpU1c3Rm1oZnFmeGVTL3hEdmdaQ2FjekpJ
VFZLCmVhQXordm12d0R6elRweC9JOEZycUkyVHowdXhUVXlTRTJGZTdQdlFqUTB5UlNMaGMxRS93
OWk4dDl5RQpOdlRyRDRqRmt4dUd4U2NSa3E0dGxMclJWVkRQWEIvQmJYRmpIdDhuUGhYOUdkSDRn
VU1mb3E2Y1Q1eGUKWjY2TVg1UlBqelpPMVFIOXVPd3lhQ05tNldON0ZUTGptWmo1cHBJeE13Q3lL
RnRSeUlnRUk3V0VDeTh0Cm9WUlgxQkpUbHdqVkUyU3lYWmRiSFkwY2t2Szdwd2FjNXoxNjFhWnR6
K1RQY3VkTHNQcmxXSG54VjZsZApsM1NuOThrV09OOVZ0VXdxeGZ2WGloaERTYmMwaWpLa2NIOXJQ
Y3V1TDZxRUdaWG9MZzNTemxpeEc2YWQKM0V6cmZwbWRvSXBWZDB1R2dQZlpNaUpBK1JOcUZUMFBY
Vk84RGREQjVpQ2Z1WW5Pd1UwRVpQSlFDQUVRCkFNU3ppem1NZGwwS3kzS1QySm4rVVBEblcreUpi
enBHay9SU2plbTFyRXNnSUFvVkM5bXZLUUNtOHlQVgpybUs1NVBsaGc0TkF5TGd5M01WeDVnazVF
R1NuSStFNmhmYzJleGl4bWZHT2lJekZIT2pHNE12bVl6dzgKdHJaNk1DZDZWa1Bla0dWaXkrajhG
SFVOY0oyQTI4SEROT1lJejZwYmE1NlJkTjVaNVpCQmpQa05rQzl1CjBXVTJCcGNlV1VpelNQSTFW
TGRGWFFreU5YNElOb2xUQm9VMWo4bUVpYmlhZ2xTMmtsRUlKV3ljamxlZgpaWUNhbTc5cE5rUm4z
TG51eWtDTEk1dUQ1UU1XQ3RQRnRpTFNLNnN4aVZiT2sydlJoazNvVGJrQTRxdlQKVmZoK1pQWkpm
czB0N1pQQnFua1RpTW1kOG5NTFh1djcxdGkxaEE4VVhzcnVnUTUyNUdEaC82T2swc24wCnE5Qmcz
V1A1VmFiSjRHVVNQSDgwVHdsQURYU21WeUFLci9KTlUrTm8vTUY3dDJJR2JJOGc0OHBoL0xSUApW
UFZpc29oY2xNMWZWdHovc0kyYWErTHB5eUVkeXk5eEMrN0pFR1h2TEdJM2ZIQWRjSDd6eFhzU04w
c0EKMVpManpQNExuY1M4Y3lGL3VrNUx0bzloRTViRklRcEdGcVRBM2lnb1pUMGVNcVJaREFHcDRV
dTNYWGgzCmpZVHcxOFpobXVTN3N1MWdFOHlUSjBpaVFpVGZQU2FXaVg3RTMrMkpmNWZBdUg1YzlQ
M1d6RFBlTDJCVQozeWtOVzRIYldQbmF6Tkd1T09Xd2o2YzBqSkZzWjcrblpIWGlZSTlqZGxGdWYz
U2o0SEVTSlNtMkZ0YUIKWVJ5bFJuTmtQRTN2MkhhVENtREYyVEZKQUJFQkFBSEN3WFlFR0FFS0FD
QUNHd3dXSVFROFIyUXVSMjRiCkY2VnJlaEVqTlZrcUgvRzIyZ1VDWnJBaFFBQUtDUkFqTlZrcUgv
RzIybjAyRC85d0x1Y1BnK3AxMHlGZApVaVhnb0dndlliRXJLNnU3NTVhN0NOd3NjT2llYTFUOHNs
YU5JbTdlOFZObVVWak1wWG51UVpsalJvdTEKOFVkMmxJL0J2N05LblNoZzhxalRhZkdycWRGeWdP
QXhtSnFMY0srNzlFbjNSVnNoUktlOXd6VGFCQStsCnhtNUtOOHdLbVRaTWl2aGtZQ3VkV1FkNnRo
Vjd5a29pZVUxTnJlM0dnc01Wem5sUFlwQm5lYlRwRXlHdgpWZGdWalVvd293QVNGWVI2M2o5RlRD
VHVGUlhycmFsUTRZM2JTMDBSL3ZxTzdhZ0ZoYlVZSTQxb0tOV0oKL0hrOFE3VW5tYTRtc3ZjNTZK
cnpCbXFqaEZMODBsWVU4anVJRXFhazA1Zzk0dk1jcmduNjR2SGdWNlRzClduMFl4QVZacVR1aExD
Q3o2UTNOOUFQVkFYZE5rWDBwNVZQUEI5NmkraGtEVkVWRzZySEhrTC9Md21NZApxbFlKeDZhRm1V
WVFVU21pa0tGbzNWaWtaMXViNUtuaVRLNDJnNDI5ckZHMEJLaWhuZXRBT3NTbXVRUkEKU21sRENt
UE85bzhrZ1FReWlCcFc4RkRiSjNhWXRramE3VHJpMS9zMGl0bHdMTkhRSUxlRmdoMDRNZEkyCnE1
eDJueEhTdEdmRENraDIvWkF3U0xHZGlKK3VaMGdYMU1jRVYrc3QvTjU0alo4UU9UeW15RExyVWNJ
awpxT1B0VkRacmJsVTJkSmN5VkhERktaNE8yQlJxMkhyNTN6ZEI4VEdjY3Mwc3pZYUpFS2hTcHZH
UGMwVU0KSDQwYnFIU2NDWlk1UDdsVHp2a0piRk0yWWNLQU9hczRNOG9MS054VHluU2psc083S08z
bGV5Ti8ySUQ0CnhhaWtxbEtqUGc9PQo9RHlndwotLS0tLUVORCBQR1AgUFVCTElDIEtFWSBCTE9D
Sy0tLS0tCg==
-----------------------3f8404d2afac3da29912430a63c7aebc--

--------3133b41c750955d357ea6884972dacdd72aa44d775ae6045761ce04775cf1d13
Content-Type: application/pgp-signature; name=&quot;signature.asc&quot;
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename=&quot;signature.asc&quot;

-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wsG5BAEBCgBtBYJqDL6xCRAjNVkqH/G22kUUAAAAAAAcACBzYWx0QG5vdGF0
aW9ucy5vcGVucGdwanMub3Jnn8QjgfSPNPDe1oYJWGAqdWroKX/e+sbzyQD4
PKLxMk8WIQQ8R2QuR24bF6VrehEjNVkqH/G22gAA2zEP/3ULkMtfIXElrpqS
HJ34S58rZtUGn+DsSMr6A7feM27aLucRn4e7dr3o8mED5JZSse+FttEP20pB
5G01PKf7fh6qZsu/mvn1JiChR3ifN8KD2Q0zcjAzoCNxzQzaFALudbcv7CEY
SIb64joHo8rZQjm+p7OFuE3q09BgsMKNXF+9Zfh/w2ihJU0khhpkTXgyyw5S
BkYkPIB+h2fOwV8j2+nQdf4JG275ZIGTZLMIjYOQaEKkzImoJlDT+V1zISjS
8o9eTh9h07S0TkwbtsfidMPSISCORrxBmpv+mHGxs2vQJEax+g07lx2AOGNc
7NoZrBTaLbri9dTJsMDID+Jg9OdDnrF6QfCld7T5cJX4KUlDZvRBSu/uQBpK
UOUDQhuHfhNWATYYCLKIVnDYYTc6+vvEB5qlwmasD4E3FFSycnhN0bDryOgM
FX7C7kVlq40MLFU0GXsx58cxjK2GiUW1dncKS10GUP/N8eFKTQvSO9oNj6w4
W/inXIavj9eoWPNb9Ng5LB1NAZCTQZh0c7TAmrnMTlmY3nwVCC1l3/UXXwBr
hiF7JaGte11o9nuyaxEysHLxar0mRpXUAifYDn5MJC6HY9MVeESbZE3xZCFz
ZlkpeX8mlfKPq61MaP52IY7fl718eOPKfZKgeVJbc74V9JflGX6nNDk+Fz33
V9Gbo+su
=4bbA
-----END PGP SIGNATURE-----


--------3133b41c750955d357ea6884972dacdd72aa44d775ae6045761ce04775cf1d13--
]