๐Ÿ” CVE Alert

CVE-2026-40026

MEDIUM 4.4

Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
2th

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.

CWE CWE-125
Vendor sleuthkit
Product sleuthkit
Published Apr 8, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for sleuthkit sleuthkit

Be the first to know when new medium vulnerabilities affecting sleuthkit sleuthkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

Affected Versions

sleuthkit / sleuthkit
0 โ‰ค 4.14.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sleuthkit/sleuthkit/pull/3445 github.com: https://github.com/sleuthkit/sleuthkit/commit/a95b0ac21733b059a517aaefa667a17e1bcbdee1 mobasi.ai: https://mobasi.ai/sentinel vulncheck.com: https://www.vulncheck.com/advisories/sleuth-kit-iso9660-susp-extension-reference-out-of-bounds-read

Credits

Mobasi Security Team