[From nobody Wed May 20 07:21:07 2026
Received: (at submit) by bugs.debian.org; 19 May 2026 19:54:04 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-20.0 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,HAS_PACKAGE,PGPSIGNATURE,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS,
 SPF_PASS autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 14; hammy, 86; neutral, 18; spammy, 1.
 spammytokens:0.941-+--H*r:bugs.debian.org
 hammytokens:0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc,
 0.000-+--HTo:N*Debian, 0.000-+--H*Ad:N*Bug, 0.000-+--H*Ad:N*Tracking
Return-path: &lt;daniel@mindani.net&gt;
Received: from mail-4327.protonmail.ch ([185.70.43.27]:18603)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;daniel@mindani.net&gt;) id 1wPQVw-008Up3-0c
 for submit@bugs.debian.org; Tue, 19 May 2026 19:54:04 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mindani.net;
 s=protonmail3; t=1779220418; x=1779479618;
 bh=jP8hdYXGGoWkYZ0u4B75kHH8OxybjIY2XgT9/EKWp/g=;
 h=Date:To:From:Subject:Message-ID:Feedback-ID:From:To:Cc:Date:
 Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector;
 b=QVPXlHqmxmgUwsPWpYkxbAHiRsWkC4TI6hNfveer3xljbQaxgViT7vT0Se5QSIdZL
 ECL1sWO0+qYgZFkFSurP2bOnAF7rE9x6UM3NM4lmZl/20k3iPbaiRkAMXrTvTyEnn0
 R4tLLAnEJO/Mbx067zlK/8YSSKlWHzzlaogzNNE+Qg7Knw4HTPr4iQ5ginkfetmSF3
 c5XkuoeZd07aZsWnHGqDcwpMwER3AHlAzr9vQfIkwOmoVyryuFXekcdnCYe4iGfipW
 mgdzC46f+jjnfYu3u28btAY7NgZEj9INcpdWs4ASmE7M8V16fQSe0a0O0vNcsvEAFd
 Kaw9v9vHTdLDw==
Date: Tue, 19 May 2026 19:53:33 +0000
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
From: Daniel Markstedt &lt;daniel@mindani.net&gt;
Subject: CVE-2026-44054: Predictable afpd session token
Message-ID: &lt;toDmeX5_nRxGw71gH5-CQPaO9Qa_3yH17Hm2Ho96KSOTyGSSpROvKm7_VEIWL1zvXPpLvo7amB_ZdjWo9pZDVMnQnSvQ6dwvqfm19pzZ-R8=@mindani.net&gt;
Feedback-ID: 84350481:user:proton
X-Pm-Message-ID: 82d9b21335c89e8f09fa32f66a4995d897cee5cd
MIME-Version: 1.0
Content-Type: multipart/signed; protocol=&quot;application/pgp-signature&quot;;
 micalg=pgp-sha512;
 boundary=&quot;------58d2d752aab100cb0721c5172d27d7951f3fd2b5efcf75cbfcb032a8cf8f0ea9&quot;;
 charset=utf-8
Delivered-To: submit@bugs.debian.org

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------58d2d752aab100cb0721c5172d27d7951f3fd2b5efcf75cbfcb032a8cf8f0ea9
Content-Type: multipart/mixed;boundary=---------------------5e2a12ebca0e9f67ab843326151edd16

-----------------------5e2a12ebca0e9f67ab843326151edd16
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;charset=utf-8

Package: netatalk
Version: 4.4.2~ds-1
Severity: critical
X-Debbugs-Cc: pkg-netatalk-devel@lists.alioth.debian.org

will be resolved by upgrading to upstream v4.4.3

-----------------------5e2a12ebca0e9f67ab843326151edd16
Content-Type: application/pgp-keys; filename=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;; name=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;; name=&quot;publickey - daniel@mindani.net - 0x3C47642E.asc&quot;

LS0tLS1CRUdJTiBQR1AgUFVCTElDIEtFWSBCTE9DSy0tLS0tCgp4c0ZOQkdUeVVBZ0JFQURDRUY2
ZHBEa3VVaGlhd21mbXVxN0tMdmhrelozM1ZPSEMwbW9LaU1ON3lpUTYKaXR1QW5mblNLUWZTVkdY
TjUvTTd5ZTQvNDIvc3dKeWRxQlNGOHMrV1k4bHpIZ0VmZk1hK2NnRitkVS9BCktjOGZVTjA2NWFT
MlJIY1h4QXBBUFp3a0c5OFdmRnBFMjVhbFNLNm1EYk82T2dCRk8zME5USmpVQlNjOAp4b1duRmp4
dmQvSk15MDVXNVJmYk56eHgzaGxYaWI5NHNnK3JzWEdVaGt5bjdxR1k4Z0paT3YydXYzaTIKc2FM
MHRpdU5OVGVxRmVydzRnN05CSzhtSzArNkNWcG01Snh4L005MGRsQmQvaGRteVRBWUhGcjlTREh0
CmtmUW1EMVZLSlIyQkx1OWhmc3JwWGlUUDdmekQ1N0JFUzZ2VjREbTZkczg0SXJBTWdPeG5SSUho
aTFtWAo2OGJnWGhEUGNWM2JIeHVLWm4wM3pWMndlYnFzaWZuOXU2elRGQnc0SmxlY2lUSHBSYTd1
anh3cy9NbzMKN3liNEpqdDNZSmd5ZE1za0ErOEZHZ09scVhpVWEwdDhrWUdIQVRTTDhJWTNFVTFJ
TnVxdlFYbWo0V0VLCit6MDVXaWp4N0hFWFdZV0VrRGlGQkQ1RlhvWWNMNHZDUlNyczR0SDl4dmV2
VERaMXdLV0RxUW1oeW94Ngo0V0p1cUdkVUpRSGNQVDA2Slk2am9FNHlFN1NjdDJJZjBoZXVtVk5v
TDh5eVNRUFFwL0N5cU9NOHp0UG0KMGJ2eHN2RjhiM0xtemFGYjkzT0RvYjd6UzB2c25HdHlqbzgv
Sm0vb1hmb3pDNG5IZ3ZqV09NRUd6VHBMCjlVRkRBSjJSRnVONUU5c2F6SGZGL3gxN2NScVptWjYv
ekx1YWFRQVJBUUFCelNWRVlXNXBaV3dnVFdGeQphM04wWldSMElEeGtZVzVwWld4QWJXbHVaR0Z1
YVM1dVpYUSt3c0dPQkJNQkNnQTRBaHNEQlFzSkNBY0MKQmhVS0NRZ0xBZ1FXQWdNQkFoNEJBaGVB
RmlFRVBFZGtMa2R1R3hlbGEzb1JJelZaS2gveHR0b0ZBbWF3CklMUUFDZ2tRSXpWWktoL3h0dG80
N3cvL1N6SEJzeDZBWlIyZzJVcFpxYXljRThGK0h4OW95YnR6ZTROWApLeHp3VFBVeER6WEFpcFFS
czBsUlBpeHpCUFQ2d005TlN4Q2lIQTJyMFhvamRVc2lPWDcxclFURzhEbnAKdkpxcW1sSnpHN1l3
QmpKVWFaQjh4MkNacjV4T1MzQjU2MHluWTdxaWZzRDM5TUdtamZzZTV4VGloYU5pCk80YzF1TmhZ
eHhVMURTS0pGWExhSzZWTXVtYytMQmw4bkErbHZZU2lSd1BrMmwvQ3g3bVdjZk1nR05PQQpDdEJr
YnpnVndNZFAvcVBwQkV2cytpRWtyNUpmVkk2aytIM29OZmd1Y0t5K0U1UWFoOEhzNEZQYTg2U3AK
QXRZdnNwSGF4NG8zWnJ2UVRyeTBSaG9XbkFlSTN5VUlpU1c3Rm1oZnFmeGVTL3hEdmdaQ2FjekpJ
VFZLCmVhQXordm12d0R6elRweC9JOEZycUkyVHowdXhUVXlTRTJGZTdQdlFqUTB5UlNMaGMxRS93
OWk4dDl5RQpOdlRyRDRqRmt4dUd4U2NSa3E0dGxMclJWVkRQWEIvQmJYRmpIdDhuUGhYOUdkSDRn
VU1mb3E2Y1Q1eGUKWjY2TVg1UlBqelpPMVFIOXVPd3lhQ05tNldON0ZUTGptWmo1cHBJeE13Q3lL
RnRSeUlnRUk3V0VDeTh0Cm9WUlgxQkpUbHdqVkUyU3lYWmRiSFkwY2t2Szdwd2FjNXoxNjFhWnR6
K1RQY3VkTHNQcmxXSG54VjZsZApsM1NuOThrV09OOVZ0VXdxeGZ2WGloaERTYmMwaWpLa2NIOXJQ
Y3V1TDZxRUdaWG9MZzNTemxpeEc2YWQKM0V6cmZwbWRvSXBWZDB1R2dQZlpNaUpBK1JOcUZUMFBY
Vk84RGREQjVpQ2Z1WW5Pd1UwRVpQSlFDQUVRCkFNU3ppem1NZGwwS3kzS1QySm4rVVBEblcreUpi
enBHay9SU2plbTFyRXNnSUFvVkM5bXZLUUNtOHlQVgpybUs1NVBsaGc0TkF5TGd5M01WeDVnazVF
R1NuSStFNmhmYzJleGl4bWZHT2lJekZIT2pHNE12bVl6dzgKdHJaNk1DZDZWa1Bla0dWaXkrajhG
SFVOY0oyQTI4SEROT1lJejZwYmE1NlJkTjVaNVpCQmpQa05rQzl1CjBXVTJCcGNlV1VpelNQSTFW
TGRGWFFreU5YNElOb2xUQm9VMWo4bUVpYmlhZ2xTMmtsRUlKV3ljamxlZgpaWUNhbTc5cE5rUm4z
TG51eWtDTEk1dUQ1UU1XQ3RQRnRpTFNLNnN4aVZiT2sydlJoazNvVGJrQTRxdlQKVmZoK1pQWkpm
czB0N1pQQnFua1RpTW1kOG5NTFh1djcxdGkxaEE4VVhzcnVnUTUyNUdEaC82T2swc24wCnE5Qmcz
V1A1VmFiSjRHVVNQSDgwVHdsQURYU21WeUFLci9KTlUrTm8vTUY3dDJJR2JJOGc0OHBoL0xSUApW
UFZpc29oY2xNMWZWdHovc0kyYWErTHB5eUVkeXk5eEMrN0pFR1h2TEdJM2ZIQWRjSDd6eFhzU04w
c0EKMVpManpQNExuY1M4Y3lGL3VrNUx0bzloRTViRklRcEdGcVRBM2lnb1pUMGVNcVJaREFHcDRV
dTNYWGgzCmpZVHcxOFpobXVTN3N1MWdFOHlUSjBpaVFpVGZQU2FXaVg3RTMrMkpmNWZBdUg1YzlQ
M1d6RFBlTDJCVQozeWtOVzRIYldQbmF6Tkd1T09Xd2o2YzBqSkZzWjcrblpIWGlZSTlqZGxGdWYz
U2o0SEVTSlNtMkZ0YUIKWVJ5bFJuTmtQRTN2MkhhVENtREYyVEZKQUJFQkFBSEN3WFlFR0FFS0FD
QUNHd3dXSVFROFIyUXVSMjRiCkY2VnJlaEVqTlZrcUgvRzIyZ1VDWnJBaFFBQUtDUkFqTlZrcUgv
RzIybjAyRC85d0x1Y1BnK3AxMHlGZApVaVhnb0dndlliRXJLNnU3NTVhN0NOd3NjT2llYTFUOHNs
YU5JbTdlOFZObVVWak1wWG51UVpsalJvdTEKOFVkMmxJL0J2N05LblNoZzhxalRhZkdycWRGeWdP
QXhtSnFMY0srNzlFbjNSVnNoUktlOXd6VGFCQStsCnhtNUtOOHdLbVRaTWl2aGtZQ3VkV1FkNnRo
Vjd5a29pZVUxTnJlM0dnc01Wem5sUFlwQm5lYlRwRXlHdgpWZGdWalVvd293QVNGWVI2M2o5RlRD
VHVGUlhycmFsUTRZM2JTMDBSL3ZxTzdhZ0ZoYlVZSTQxb0tOV0oKL0hrOFE3VW5tYTRtc3ZjNTZK
cnpCbXFqaEZMODBsWVU4anVJRXFhazA1Zzk0dk1jcmduNjR2SGdWNlRzClduMFl4QVZacVR1aExD
Q3o2UTNOOUFQVkFYZE5rWDBwNVZQUEI5NmkraGtEVkVWRzZySEhrTC9Md21NZApxbFlKeDZhRm1V
WVFVU21pa0tGbzNWaWtaMXViNUtuaVRLNDJnNDI5ckZHMEJLaWhuZXRBT3NTbXVRUkEKU21sRENt
UE85bzhrZ1FReWlCcFc4RkRiSjNhWXRramE3VHJpMS9zMGl0bHdMTkhRSUxlRmdoMDRNZEkyCnE1
eDJueEhTdEdmRENraDIvWkF3U0xHZGlKK3VaMGdYMU1jRVYrc3QvTjU0alo4UU9UeW15RExyVWNJ
awpxT1B0VkRacmJsVTJkSmN5VkhERktaNE8yQlJxMkhyNTN6ZEI4VEdjY3Mwc3pZYUpFS2hTcHZH
UGMwVU0KSDQwYnFIU2NDWlk1UDdsVHp2a0piRk0yWWNLQU9hczRNOG9MS054VHluU2psc083S08z
bGV5Ti8ySUQ0CnhhaWtxbEtqUGc9PQo9RHlndwotLS0tLUVORCBQR1AgUFVCTElDIEtFWSBCTE9D
Sy0tLS0tCg==
-----------------------5e2a12ebca0e9f67ab843326151edd16--

--------58d2d752aab100cb0721c5172d27d7951f3fd2b5efcf75cbfcb032a8cf8f0ea9
Content-Type: application/pgp-signature; name=&quot;signature.asc&quot;
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename=&quot;signature.asc&quot;

-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wsG5BAEBCgBtBYJqDL+uCRAjNVkqH/G22kUUAAAAAAAcACBzYWx0QG5vdGF0
aW9ucy5vcGVucGdwanMub3JnaH2JajkCfE+spQRPtlrtwEgMirSX+WSjdg3B
go2PXdAWIQQ8R2QuR24bF6VrehEjNVkqH/G22gAAnssP/ieR71vODDVuovxp
Jp0Hcx4qbr6J30nCTtUx7Hc3Epz2hx5QdLFMeOvaXSkqVziikQH9FApnqDCS
pMtJjauQn9H8xllEY2+U6/xnvdMryPoM4PJRmVpJBFMl9cl39p1Sb81xc6lP
0VOHC7b6famheJ6FOvzPcJmvtN3sRnvyNqhnhd0Spl+dwcR5eG172ISFkSuh
8RwHMBHGHOqta6xdbmCccflveaLmbN4MkjC2ggUcpTOezNboAEOyQaaXvjPT
XIQVhDkveBL3yJN9kGpvt6LpCPJ0vCL13ppFe5TVY6d/AMzwVT2Bx03/9xNB
OfoF8+f2vTvN92E3/I1mKuincBhYW2+yiN+owbXoyvyhR0+5W9XepWH9pt6k
E9CYB801UvYNsAKQQAt1ZX695a8LJUwwvm5gcCeQx+gPOVIlveXAC8Ohusn2
Fb7MNabEZTWkP2lUy9rymoH7q422ESx426KNRu9NV1N8iUSP/l4vv0h7uLli
01hVIq3sgSgXDq+rd149j7HytVcQOPcmXxmCA2mZSxu8yRApUzzIRAFeRnAF
QUXFb5NNbdOgRmVh8oGVBtbQKzW2zhmQhuIKYn9+zunm0vy4gOg0ppani5RW
vm0iXLa8VSquuEs/So9kzcSwKHA3mMY2i8zBjV9NAA5nwCt9nPW3AmfPV5Qw
+DtJ8bdr
=O/8Y
-----END PGP SIGNATURE-----


--------58d2d752aab100cb0721c5172d27d7951f3fd2b5efcf75cbfcb032a8cf8f0ea9--
]