CVE-2026-40026: Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
Published Apr 8, 2026
·Updated
Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
Other sources
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parsesusp() function trusts lenid, lendes, and lensrc fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.
— NVD
Affected Software
2 affected componentsFixes available
Microsoft azl3 sleuthkit 4.12.1-1
sleuthkit The Sleuth Kit<4.14.0
Remediation
Event History
Apr 8, 2026
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 10, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity