[From nobody Wed May 20 07:21:11 2026
Received: (at submit) by bugs.debian.org; 19 May 2026 20:00:53 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-20.0 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,HAS_PACKAGE,PGPSIGNATURE,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS,
 SPF_PASS autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 15; hammy, 89; neutral, 17; spammy, 1.
 spammytokens:0.941-+--H*r:bugs.debian.org
 hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc,
 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug, 0.000-+--H*Ad:N*Tracking
Return-path: &lt;daniel@mindani.net&gt;
Received: from mail-4318.protonmail.ch ([185.70.43.18]:12677)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;daniel@mindani.net&gt;) id 1wPQcX-008Vgs-2H
 for submit@bugs.debian.org; Tue, 19 May 2026 20:00:53 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mindani.net;
 s=protonmail3; t=1779220852; x=1779480052;
 bh=EmkyHG9eZ6ApHWMjOmZiYV0EZXM4o67lougeSG2krNc=;
 h=Date:To:From:Subject:Message-ID:Feedback-ID:From:To:Cc:Date:
 Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector;
 b=JFPfnitq3oqh5J06SViI21o9zDrTLSK4XB5xpem8wmXh4zrj8i+yFesnlT64CSbPY
 DXcM0z8JU/O/MANsUzfrNeOnzJRHrtt4NZ5SqfgzbdTg9SiYgpptJ8ZelMcfJ+UYPN
 QVO2rIaQgKNqJVXX/fckBbfmGm7HwK2RPXVjjAYDg33Qm4eEa0jdvnTQ5mfu8ulaqg
 UbXc3YR0VkyfSgHM3ywXFnhvyDcP5vIcVeZUFkj5lQ2qWzhbWIU/GuRGisfgnbRqHS
 sl+6nCYKXkoiQwU/CcM7fNWYE5LGxca0g9XX6tYymqCaQKeC2mt59OIrjGn/IV5bG5
 05iDa6rBdzLSw==
Date: Tue, 19 May 2026 20:00:49 +0000
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
From: Daniel Markstedt &lt;daniel@mindani.net&gt;
Subject: CVE-2026-45354: Pre-authentication DSI protocol desync
Message-ID: &lt;Hp7nzc7Y5lasJlhJIugVBKlnhr08K01rg-KInsJkJz0CTVnY9mxtLIQDUAes7UM_zfCHvu821cQtObPSYknQWdVRVhtBCBqfMsQfVD8xARs=@mindani.net&gt;
Feedback-ID: 84350481:user:proton
X-Pm-Message-ID: 16c96a3081ab6fd8a11394087e0ba660e6ee16c5
MIME-Version: 1.0
Content-Type: multipart/signed; protocol=&quot;application/pgp-signature&quot;;
 micalg=pgp-sha512;
 boundary=&quot;------2dd9d6ccd15839954339847c84dfb5129e071016150bd41f71825fcf523e8ff0&quot;;
 charset=utf-8
Delivered-To: submit@bugs.debian.org
X-CrossAssassin-Score: 9

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------2dd9d6ccd15839954339847c84dfb5129e071016150bd41f71825fcf523e8ff0
Content-Type: multipart/mixed;boundary=---------------------d65878dcd8874fadcaa6a8f1b553e2b9

-----------------------d65878dcd8874fadcaa6a8f1b553e2b9
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;charset=utf-8

Package: netatalk
Version: 4.4.2~ds-1
Severity: critical
X-Debbugs-Cc: pkg-netatalk-devel@lists.alioth.debian.org

will be resolved by upgrading to upstream v4.4.3

-----------------------d65878dcd8874fadcaa6a8f1b553e2b9
Content-Type: application/pgp-keys; filename=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;; name=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;; name=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;

LS0tLS1CRUdJTiBQR1AgUFVCTElDIEtFWSBCTE9DSy0tLS0tCgp4c0ZOQkdUeVVBZ0JFQURDRUY2
ZHBEa3VVaGlhd21mbXVxN0tMdmhrelozM1ZPSEMwbW9LaU1ON3lpUTYKaXR1QW5mblNLUWZTVkdY
TjUvTTd5ZTQvNDIvc3dKeWRxQlNGOHMrV1k4bHpIZ0VmZk1hK2NnRitkVS9BCktjOGZVTjA2NWFT
MlJIY1h4QXBBUFp3a0c5OFdmRnBFMjVhbFNLNm1EYk82T2dCRk8zME5USmpVQlNjOAp4b1duRmp4
dmQvSk15MDVXNVJmYk56eHgzaGxYaWI5NHNnK3JzWEdVaGt5bjdxR1k4Z0paT3YydXYzaTIKc2FM
MHRpdU5OVGVxRmVydzRnN05CSzhtSzArNkNWcG01Snh4L005MGRsQmQvaGRteVRBWUhGcjlTREh0
CmtmUW1EMVZLSlIyQkx1OWhmc3JwWGlUUDdmekQ1N0JFUzZ2VjREbTZkczg0SXJBTWdPeG5SSUho
aTFtWAo2OGJnWGhEUGNWM2JIeHVLWm4wM3pWMndlYnFzaWZuOXU2elRGQnc0SmxlY2lUSHBSYTd1
anh3cy9NbzMKN3liNEpqdDNZSmd5ZE1za0ErOEZHZ09scVhpVWEwdDhrWUdIQVRTTDhJWTNFVTFJ
TnVxdlFYbWo0V0VLCit6MDVXaWp4N0hFWFdZV0VrRGlGQkQ1RlhvWWNMNHZDUlNyczR0SDl4dmV2
VERaMXdLV0RxUW1oeW94Ngo0V0p1cUdkVUpRSGNQVDA2Slk2am9FNHlFN1NjdDJJZjBoZXVtVk5v
TDh5eVNRUFFwL0N5cU9NOHp0UG0KMGJ2eHN2RjhiM0xtemFGYjkzT0RvYjd6UzB2c25HdHlqbzgv
Sm0vb1hmb3pDNG5IZ3ZqV09NRUd6VHBMCjlVRkRBSjJSRnVONUU5c2F6SGZGL3gxN2NScVptWjYv
ekx1YWFRQVJBUUFCelNWRVlXNXBaV3dnVFdGeQphM04wWldSMElEeGtZVzVwWld4QWJXbHVaR0Z1
YVM1dVpYUSt3c0dPQkJNQkNnQTRBaHNEQlFzSkNBY0MKQmhVS0NRZ0xBZ1FXQWdNQkFoNEJBaGVB
RmlFRVBFZGtMa2R1R3hlbGEzb1JJelZaS2gveHR0b0ZBbWF3CklMUUFDZ2tRSXpWWktoL3h0dG80
N3cvL1N6SEJzeDZBWlIyZzJVcFpxYXljRThGK0h4OW95YnR6ZTROWApLeHp3VFBVeER6WEFpcFFS
czBsUlBpeHpCUFQ2d005TlN4Q2lIQTJyMFhvamRVc2lPWDcxclFURzhEbnAKdkpxcW1sSnpHN1l3
QmpKVWFaQjh4MkNacjV4T1MzQjU2MHluWTdxaWZzRDM5TUdtamZzZTV4VGloYU5pCk80YzF1TmhZ
eHhVMURTS0pGWExhSzZWTXVtYytMQmw4bkErbHZZU2lSd1BrMmwvQ3g3bVdjZk1nR05PQQpDdEJr
YnpnVndNZFAvcVBwQkV2cytpRWtyNUpmVkk2aytIM29OZmd1Y0t5K0U1UWFoOEhzNEZQYTg2U3AK
QXRZdnNwSGF4NG8zWnJ2UVRyeTBSaG9XbkFlSTN5VUlpU1c3Rm1oZnFmeGVTL3hEdmdaQ2FjekpJ
VFZLCmVhQXordm12d0R6elRweC9JOEZycUkyVHowdXhUVXlTRTJGZTdQdlFqUTB5UlNMaGMxRS93
OWk4dDl5RQpOdlRyRDRqRmt4dUd4U2NSa3E0dGxMclJWVkRQWEIvQmJYRmpIdDhuUGhYOUdkSDRn
VU1mb3E2Y1Q1eGUKWjY2TVg1UlBqelpPMVFIOXVPd3lhQ05tNldON0ZUTGptWmo1cHBJeE13Q3lL
RnRSeUlnRUk3V0VDeTh0Cm9WUlgxQkpUbHdqVkUyU3lYWmRiSFkwY2t2Szdwd2FjNXoxNjFhWnR6
K1RQY3VkTHNQcmxXSG54VjZsZApsM1NuOThrV09OOVZ0VXdxeGZ2WGloaERTYmMwaWpLa2NIOXJQ
Y3V1TDZxRUdaWG9MZzNTemxpeEc2YWQKM0V6cmZwbWRvSXBWZDB1R2dQZlpNaUpBK1JOcUZUMFBY
Vk84RGREQjVpQ2Z1WW5Pd1UwRVpQSlFDQUVRCkFNU3ppem1NZGwwS3kzS1QySm4rVVBEblcreUpi
enBHay9SU2plbTFyRXNnSUFvVkM5bXZLUUNtOHlQVgpybUs1NVBsaGc0TkF5TGd5M01WeDVnazVF
R1NuSStFNmhmYzJleGl4bWZHT2lJekZIT2pHNE12bVl6dzgKdHJaNk1DZDZWa1Bla0dWaXkrajhG
SFVOY0oyQTI4SEROT1lJejZwYmE1NlJkTjVaNVpCQmpQa05rQzl1CjBXVTJCcGNlV1VpelNQSTFW
TGRGWFFreU5YNElOb2xUQm9VMWo4bUVpYmlhZ2xTMmtsRUlKV3ljamxlZgpaWUNhbTc5cE5rUm4z
TG51eWtDTEk1dUQ1UU1XQ3RQRnRpTFNLNnN4aVZiT2sydlJoazNvVGJrQTRxdlQKVmZoK1pQWkpm
czB0N1pQQnFua1RpTW1kOG5NTFh1djcxdGkxaEE4VVhzcnVnUTUyNUdEaC82T2swc24wCnE5Qmcz
V1A1VmFiSjRHVVNQSDgwVHdsQURYU21WeUFLci9KTlUrTm8vTUY3dDJJR2JJOGc0OHBoL0xSUApW
UFZpc29oY2xNMWZWdHovc0kyYWErTHB5eUVkeXk5eEMrN0pFR1h2TEdJM2ZIQWRjSDd6eFhzU04w
c0EKMVpManpQNExuY1M4Y3lGL3VrNUx0bzloRTViRklRcEdGcVRBM2lnb1pUMGVNcVJaREFHcDRV
dTNYWGgzCmpZVHcxOFpobXVTN3N1MWdFOHlUSjBpaVFpVGZQU2FXaVg3RTMrMkpmNWZBdUg1YzlQ
M1d6RFBlTDJCVQozeWtOVzRIYldQbmF6Tkd1T09Xd2o2YzBqSkZzWjcrblpIWGlZSTlqZGxGdWYz
U2o0SEVTSlNtMkZ0YUIKWVJ5bFJuTmtQRTN2MkhhVENtREYyVEZKQUJFQkFBSEN3WFlFR0FFS0FD
QUNHd3dXSVFROFIyUXVSMjRiCkY2VnJlaEVqTlZrcUgvRzIyZ1VDWnJBaFFBQUtDUkFqTlZrcUgv
RzIybjAyRC85d0x1Y1BnK3AxMHlGZApVaVhnb0dndlliRXJLNnU3NTVhN0NOd3NjT2llYTFUOHNs
YU5JbTdlOFZObVVWak1wWG51UVpsalJvdTEKOFVkMmxJL0J2N05LblNoZzhxalRhZkdycWRGeWdP
QXhtSnFMY0srNzlFbjNSVnNoUktlOXd6VGFCQStsCnhtNUtOOHdLbVRaTWl2aGtZQ3VkV1FkNnRo
Vjd5a29pZVUxTnJlM0dnc01Wem5sUFlwQm5lYlRwRXlHdgpWZGdWalVvd293QVNGWVI2M2o5RlRD
VHVGUlhycmFsUTRZM2JTMDBSL3ZxTzdhZ0ZoYlVZSTQxb0tOV0oKL0hrOFE3VW5tYTRtc3ZjNTZK
cnpCbXFqaEZMODBsWVU4anVJRXFhazA1Zzk0dk1jcmduNjR2SGdWNlRzClduMFl4QVZacVR1aExD
Q3o2UTNOOUFQVkFYZE5rWDBwNVZQUEI5NmkraGtEVkVWRzZySEhrTC9Md21NZApxbFlKeDZhRm1V
WVFVU21pa0tGbzNWaWtaMXViNUtuaVRLNDJnNDI5ckZHMEJLaWhuZXRBT3NTbXVRUkEKU21sRENt
UE85bzhrZ1FReWlCcFc4RkRiSjNhWXRramE3VHJpMS9zMGl0bHdMTkhRSUxlRmdoMDRNZEkyCnE1
eDJueEhTdEdmRENraDIvWkF3U0xHZGlKK3VaMGdYMU1jRVYrc3QvTjU0alo4UU9UeW15RExyVWNJ
awpxT1B0VkRacmJsVTJkSmN5VkhERktaNE8yQlJxMkhyNTN6ZEI4VEdjY3Mwc3pZYUpFS2hTcHZH
UGMwVU0KSDQwYnFIU2NDWlk1UDdsVHp2a0piRk0yWWNLQU9hczRNOG9MS054VHluU2psc083S08z
bGV5Ti8ySUQ0CnhhaWtxbEtqUGc9PQo9RHlndwotLS0tLUVORCBQR1AgUFVCTElDIEtFWSBCTE9D
Sy0tLS0tCg==
-----------------------d65878dcd8874fadcaa6a8f1b553e2b9--

--------2dd9d6ccd15839954339847c84dfb5129e071016150bd41f71825fcf523e8ff0
Content-Type: application/pgp-signature; name=&quot;signature.asc&quot;
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename=&quot;signature.asc&quot;

-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wsG5BAEBCgBtBYJqDMFjCRAjNVkqH/G22kUUAAAAAAAcACBzYWx0QG5vdGF0
aW9ucy5vcGVucGdwanMub3Jn/9mnAIDDVIFf3uLgajoBPQZTG4VhYiyltCNI
HK0DCjcWIQQ8R2QuR24bF6VrehEjNVkqH/G22gAAj2sP/0pFureQ0RngzJNw
Vpyj8jCzJxiP/YvTKAiLg9iZ9pLc2+HWob3kH6jnGQzNA18eDgfMbRwo61w8
PeFPAzIBfqgboe5nYHVyu0NupEblcrKG5cFT/kXvhEtCutCzSUi/iPKehxtJ
CvmuGefiqjFIDq64n8EzXUsum2ERxjbNi2uMr7vuT1TYp8f8AdJy80ipqJI4
AQJj2SVDejU9gA6X4l4tjEuhRNts/naLbG5Z6vZYuk7iFqIi/kyX9IZAASjc
P1sl+TEFY9i0AYS/TiNl9eSX9VTOJnG2pI2gQPvMCh6v/YTiwAQwjQADqdfU
9XmJlHRDbtM0iD5k2jA3qPSorMu/uTLOs/Lhi7f8iRmiCTCrLOtc23e8uuqG
rzqZlqdLK3t5YyqNOl/5y02wjrbaPbDum/W5PFCx4JKTdXZxjFBUbSgyUAuA
NS0p+56PyNO82eVJ50SnHjewaIdcu3RAyklLuM6XXnCoH9fjixbJX+ZW03CT
LMxNCIIxBUBXP/Maj3RivMZ+r/1mv87oKg9mmUV/b0CJKOJXM8scHLb4z6MR
szFEfEClWnTBm/pkt8TfZ0SFltIlUmZdCrmi+NbuQDpS/cxUv7gS047v0SEG
iJLdZMr3QKzuhmWCJGy08AWYNa52e/wMQnb2/WYev4COvDbYfuJFk1hwbrDe
7rHQn0jm
=IXYL
-----END PGP SIGNATURE-----


--------2dd9d6ccd15839954339847c84dfb5129e071016150bd41f71825fcf523e8ff0--
]