{"id":"CVE-2026-40026","summary":"Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read","details":"The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.","modified":"2026-08-12T16:24:00.696137Z","published":"2026-04-08T21:35:22.278Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40026.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-125"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40026.json"},{"type":"ADVISORY","url":"https://mobasi.ai/sentinel"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40026"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sleuth-kit-iso9660-susp-extension-reference-out-of-bounds-read"},{"type":"REPORT","url":"https://github.com/sleuthkit/sleuthkit/pull/3445"},{"type":"FIX","url":"https://github.com/sleuthkit/sleuthkit/commit/a95b0ac21733b059a517aaefa667a17e1bcbdee1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sleuthkit/sleuthkit","events":[{"introduced":"0"},{"fixed":"c6efd66293546b9c95637be703c7c7823e950629"},{"fixed":"a95b0ac21733b059a517aaefa667a17e1bcbdee1"}],"database_specific":{"cpe":"cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.14.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["ct-3.15.0","sleuthkit-4.14.0","ct-3.13.0","ct-3.12.0","ct-3.9.0","ct-3.6.0","sleuthkit-4.12.0","ct-3.5.0","sleuthkit-4.6.3","sleuthkit-4.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40026.json","vanir_signatures_modified":"2026-08-12T16:24:00Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/sleuthkit/sleuthkit/commit/a95b0ac21733b059a517aaefa667a17e1bcbdee1","target":{"file":"tsk/fs/iso9660.c","function":"parse_susp"},"deprecated":false,"digest":{"function_hash":"212127960176410529911794671586102054610","length":6782},"id":"CVE-2026-40026-52c166b8","signature_type":"Function"},{"source":"https://github.com/sleuthkit/sleuthkit/commit/a95b0ac21733b059a517aaefa667a17e1bcbdee1","target":{"file":"tsk/fs/iso9660.c"},"deprecated":false,"digest":{"line_hashes":["233558539092633722574665736049748176711","195765578056426174488118137892417144452","60344071820959405280678960589084282209","30900867453472729781591183520589254674","243313524976303149634136105029593070916","275359967314075872764190083014762687939","123671940847300039662671464355675810865","138343585418704777014505504429952598696","38017850216024956619190787057402841864","228986220772744542915084647134351797081","340239638963595765643138732219529893158","188877334575074896663267779004443891551","303550560808725321329088936313682651744","196343806790188397007908359305807735024","55171051598707546203464623365811017667","40510232904825946714020872196767733044","247436399879193791428641180943678371497","40537551830046973177627599348292889442","146644032589958185711943832325022981103"],"threshold":0.9},"id":"CVE-2026-40026-91875b52","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"}]}