---
id: CVE-2026-40026
title: Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read
summary: >-
  The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in
  the ISO9660 filesystem parser where the parse_susp() function trusts len_id,
  len_des, and len_src fields from the disk image to memcpy data into a stack
  buffer…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'
cvssSource: cna
cwe:
  - CWE-125
vendor: sleuthkit
product: sleuthkit
affected:
  - sleuthkit <= 4.14.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-04-09T19:38:20.459891Z'
published: '2026-04-08'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:20.067Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-40026'
references:
  - url: 'https://github.com/sleuthkit/sleuthkit/pull/3445'
    label: Pull Request
  - url: >-
      https://github.com/sleuthkit/sleuthkit/commit/a95b0ac21733b059a517aaefa667a17e1bcbdee1
    label: Patch Commit
  - url: 'https://mobasi.ai/sentinel'
    label: Mobasi Sentinel Vulnerability Index
  - url: >-
      https://www.vulncheck.com/advisories/sleuth-kit-iso9660-susp-extension-reference-out-of-bounds-read
    label: >-
      VulnCheck Advisory: Sleuth Kit ISO9660 SUSP Extension Reference
      Out-of-Bounds Read
tags:
  - cve.org
epss: 0.00181
epssPercentile: 0.06928
ingestedAt: '2026-10-01T19:58:57.575Z'
---

## Overview

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.

## Affected

- `sleuthkit <= 4.14.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
