CVE-2026-40025: Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
Sleuth Kit APFS Keybag Parser Out-of-Bounds Read
Other sources
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrappedkeyparser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS disk image that triggers information disclosure or crashes when processed by any Sleuth Kit tool that parses APFS volumes.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40025?
CVE-2026-40025 is classified as a medium severity vulnerability due to the potential for an out-of-bounds read that could lead to information disclosure.
How do I fix CVE-2026-40025?
To fix CVE-2026-40025, update the Sleuth Kit to version 4.15.0 or higher, as this version addresses the vulnerability.
Which versions of the Sleuth Kit are affected by CVE-2026-40025?
CVE-2026-40025 affects all versions of the Sleuth Kit up to and including 4.14.0.
What vulnerabilities does CVE-2026-40025 introduce?
CVE-2026-40025 introduces an out-of-bounds read vulnerability that could be exploited by an attacker to read memory outside the allocated bounds.
Is CVE-2026-40025 specific to any operating systems?
CVE-2026-40025 is related to the Sleuth Kit and specifically affects its APFS keybag parser functionality, regardless of the underlying operating system.