OVERVIEW CVE-2026-40026 is an out-of-bounds read vulnerability in The Sleuth Kit versions through 4.14.0, affecting the ISO9660 filesystem parser. The parse_susp() function fails to validate length fields (len_id, len_des, and len_src) from disk image metadata before performing memory operations, allowing reads beyond allocated buffer boundaries. Additionally, zero-length SUSP entries can trigger infinite parsing loops, causing denial of service conditions. SEVERITY This vulnerability carries a CVSS 7.1 HIGH rating with a local attack vector requiring user interaction. The attack has low complexity and requires no privileges, making it relatively easy to exploit. The primary impacts include high confidentiality risk through out-of-bounds information disclosure and high availability risk from potential system crashes or hangs. An attacker can craft a malicious ISO image to trigger these conditions when processed by affected systems. EXPLOITATION STATUS The vulnerability is currently listed on the KEV Catalog as active, indicating elevated concern within the cybersecurity community despite the low EPSS score of 0.00012. No publicly available exploit code has been confirmed at this time. The presence on the active Hot List suggests ongoing monitoring and potential exploitation attempts, warranting prompt patching of affected Sleuth Kit installations in forensic and security analysis environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.14.0CPE matchmatch criteria | cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:* | ||
>= 0, <= 4.14.0CPE match | cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.