PT-2026-31462 · Unknown · The Sleuth Kit

Mobasi

·

Published

2026-04-08

·

Updated

2026-04-17

·

CVE-2026-40025

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions The Sleuth Kit versions through 4.14.0
Description The Sleuth Kit contains a flaw in the APFS filesystem keybag parser. The wrapped key parser class does not properly validate length fields, leading to potential out-of-bounds reads when processing attacker-controlled data. This can result in information disclosure or application crashes when handling malicious APFS disk images.
Recommendations Update to a version beyond 4.14.0.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-40025
OESA-2026-1936
OESA-2026-1937
OESA-2026-1938
OESA-2026-1939

Affected Products

The Sleuth Kit