CVE-2026-40025: Sleuth Kit APFS Keybag Parser Out-of-Bounds Read

Published Apr 8, 2026
·
Updated

Sleuth Kit APFS Keybag Parser Out-of-Bounds Read

Other sources

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrappedkeyparser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS disk image that triggers information disclosure or crashes when processed by any Sleuth Kit tool that parses APFS volumes.

NVD

Affected Software

2 affected componentsFixes available
Microsoft azl3 sleuthkit 4.12.1-1
sleuthkit The Sleuth Kit<4.15.0

Event History

Apr 8, 2026
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 10, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-40025?

CVE-2026-40025 is classified as a medium severity vulnerability due to the potential for an out-of-bounds read that could lead to information disclosure.

2

How do I fix CVE-2026-40025?

To fix CVE-2026-40025, update the Sleuth Kit to version 4.15.0 or higher, as this version addresses the vulnerability.

3

Which versions of the Sleuth Kit are affected by CVE-2026-40025?

CVE-2026-40025 affects all versions of the Sleuth Kit up to and including 4.14.0.

4

What vulnerabilities does CVE-2026-40025 introduce?

CVE-2026-40025 introduces an out-of-bounds read vulnerability that could be exploited by an attacker to read memory outside the allocated bounds.

5

Is CVE-2026-40025 specific to any operating systems?

CVE-2026-40025 is related to the Sleuth Kit and specifically affects its APFS keybag parser functionality, regardless of the underlying operating system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203