Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82007.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-82007
Upstream
Published
2026-04-08T22:16:22Z
Modified
2026-09-19T05:33:49Z
Summary
CVE-2026-40024 affecting package sleuthkit for versions less than 4.12.1-2
Details

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tsk_recover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries.

References

Affected packages

Azure Linux:3 / sleuthkit

Package

Name
sleuthkit
Purl
pkg:rpm/azure-linux/sleuthkit

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.12.1-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82007.json"