{"id":"CVE-2026-40025","summary":"Sleuth Kit APFS Keybag Parser Out-of-Bounds Read","details":"The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS disk image that triggers information disclosure or crashes when processed by any Sleuth Kit tool that parses APFS volumes.","modified":"2026-08-12T16:24:01.475307Z","published":"2026-04-08T21:35:21.537Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40025.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40025.json"},{"type":"ADVISORY","url":"https://mobasi.ai/sentinel"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40025"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sleuth-kit-apfs-keybag-parser-out-of-bounds-read"},{"type":"REPORT","url":"https://github.com/sleuthkit/sleuthkit/pull/3444"},{"type":"FIX","url":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sleuthkit/sleuthkit","events":[{"introduced":"0"},{"fixed":"01de0345edaa1ebf21dba6939a7c6bc7129e6e7d"},{"fixed":"8b9c9e7d493bd68624f3b1a3963edd45c3ff7611"}],"database_specific":{"cpe":"cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.15.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["ct-3.15.0","sleuthkit-4.14.0","ct-3.13.0","ct-3.12.0","ct-3.9.0","ct-3.6.0","sleuthkit-4.12.0","ct-3.5.0","sleuthkit-4.6.3","sleuthkit-4.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40025.json","vanir_signatures_modified":"2026-08-12T16:24:01Z","vanir_signatures":[{"source":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","target":{"file":"tsk/fs/apfs.cpp","function":"APFSKeybag::get_key"},"deprecated":false,"digest":{"function_hash":"64676707899275895585818978114147020768","length":721},"id":"CVE-2026-40025-0f9448fe","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"70860106093143932909002113358386148011","length":2277},"id":"CVE-2026-40025-38dff4cd","signature_type":"Function","signature_version":"v1","source":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","target":{"file":"tsk/fs/apfs.cpp","function":"APFSFileSystem::init_crypto_info"}},{"digest":{"line_hashes":["37442709601541052798385986290552953502","330927510266086804026411862520987195896","265256334558563411650241984127391742847","128127207950606374510166884818947191815","60300601898860241774149135517784200760","37936624773768353234005371727484133208","959709857445969514696018278871033734","214634036834192920441630090271407171215","124393334606449290637689122721506905060","101399933198801770788635357162510699462","147907001026773307721333262357934974623","231319378934227667040132396155225488988","59004572233820187235358873497281195622","48165441581517701210196598607498289125","111035410917538237416275652627685959993"],"threshold":0.9},"id":"CVE-2026-40025-731aaac5","signature_type":"Line","signature_version":"v1","source":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","target":{"file":"tsk/fs/tsk_apfs.hpp"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","target":{"file":"tsk/fs/apfs.cpp","function":"APFSKeybag::get_keys"},"deprecated":false,"digest":{"function_hash":"250760894234121438644298776823776794828","length":599},"id":"CVE-2026-40025-ae2f908e"},{"digest":{"line_hashes":["44744225820494273369880977052167228261","180010761206456122236138658015084689392","161453428347210214231089686866503034307","21572244893218339400230498055414819554","336198626884608305243511958033320413510","41767613342464754023795775815528750427","238984329497279217678133891883350090249","1200754526259358260945358585210718560","115389981840537399986780610240560672597","217551021807021999764424498324325306905","27506872341352011404436529381244539172","203163587641978296069594618808316110565","271039927439895749350504403069447845139","117244831814786084052910525848357658900","19372117138359884362045940422287447378","278677445476748611473500501820995489193","278250128894720362209983302471143899700","199831459830172235185565741252710885593","37013995593185470514534241007342719291","190977131921202718114121948404910515634","214614100121332571942102360637723639096","3191927802976125608768968205127494069","71037076657905281452429628740993524474","324876657875692197432551497956369891880","53329671876317753096044388839930192793","243094771175642492497883813552006721265","132930741346614571257060579542209406965","209318891626891132407303122135886965817","323236925055601547390185518568183915097","291751628160302385920452952560025742230","122013124204030366207479160960530824837","126960158200876722898627114448441158011","265939483808143275831520586762212382019","71779912697480605916828320659384054577","253624769557016988580365828682420072773","174076266673209130548104760260465977698","109897709471083490354414593867530683585","138434616657635560091980470109674184431","216188185278704649898698487217397273459","239230328560481898629724076308003114336","219917262602936863014811460558092375446","198679787452635976405818557931482042723","282145444427506793112567483712630468032","220540907875251304657766866391113330436","222041839562780184884956574785612309256","241318206651622518168146412590371253342","108476234158927923328351102279703786394","191312174658110827119681483136242380799","47039940033356453741649139683607509680","145633968383706278433026439288519638592","149055279751284581105197710496243695122","262984209677934837496087688843683987144","297536184940427700511535542250282150853","161599721659678611685617849960553523850","300447280739090168781560499383220511365","180481262857623082665319941467544820756","109028383424286850382876106721502844132","34988862257584743656284184409382139471","208303685787090879902522660435288795629","270483471289629961197399830159679469779","273448191588493383581888515975733710427","161537006792173799429012808054013127404","44821822421323015426794226751515516389","261527915149566437005375164311017203620","39510200941079978873642955980447978264","54636436020523826476398328692125963773","5756248957323445813567586873357925753","337113119957916620307728926919119922161","196070942677259903122998198828237770371","79205893184857852306355773504511631797","123545156256320385558656657060790422021","100527977039555589565616549697434195131","203525146572969340923238720334657101021","127715142805339802069408731417506936846","114183752979334440243402184742992548928","305071326832422290213604443423951795257","225254968641268422031234968104127909729","204260172524095202571742313419448705078","25102529298056001258630535615961992562","251372105834751168860117090151897816226","207968418051447245158514267136311395920"],"threshold":0.9},"id":"CVE-2026-40025-c7dc84ef","signature_type":"Line","signature_version":"v1","source":"https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611","target":{"file":"tsk/fs/apfs.cpp"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"}]}