Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40026

31
FAUCET Score

OVERVIEW CVE-2026-40026 is an out-of-bounds read vulnerability in The Sleuth Kit versions through 4.14.0, affecting the ISO9660 filesystem parser. The parse_susp() function fails to validate length fields (len_id, len_des, and len_src) from disk image metadata before performing memory operations, allowing reads beyond allocated buffer boundaries. Additionally, zero-length SUSP entries can trigger infinite parsing loops, causing denial of service conditions. SEVERITY This vulnerability carries a CVSS 7.1 HIGH rating with a local attack vector requiring user interaction. The attack has low complexity and requires no privileges, making it relatively easy to exploit. The primary impacts include high confidentiality risk through out-of-bounds information disclosure and high availability risk from potential system crashes or hangs. An attacker can craft a malicious ISO image to trigger these conditions when processed by affected systems. EXPLOITATION STATUS The vulnerability is currently listed on the KEV Catalog as active, indicating elevated concern within the cybersecurity community despite the low EPSS score of 0.00012. No publicly available exploit code has been confirmed at this time. The presence on the active Hot List suggests ongoing monitoring and potential exploitation attempts, warranting prompt patching of affected Sleuth Kit installations in forensic and security analysis environments.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.0CPE matchmatch criteria
cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*
>= 0, <= 4.14.0CPE match
cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.8MEDIUM

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 1st percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 sleuthkit 4.12.1-1 on Azure Linux 3.0Fixed in: 4.12.1-2
microsoftpatch availablevia msrc
Product: 20112-17084Fixed in: 4.12.1-2

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-40026Moderate

Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read

Apr 2, 2026

References

github.com / sleuthkit/sleuthkit/commit/a95b0ac21733b059a517aaefa667a17e1bcbdee1
Patch
github.com / sleuthkit/sleuthkit/pull/3445
Issue Tracking
mobasi.ai / sentinel
Third Party Advisory
vulncheck.com / advisories/sleuth-kit-iso9660-susp-extension-reference-out-of-bounds-read
Third Party Advisory