The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrappedkeyparser class follows attacker-controlled length fields without bounds checking, causing heap reads past the allocated buffer. An attacker can craft a malicious APFS disk image that triggers information disclosure or crashes when processed by any Sleuth Kit tool that parses APFS volumes.
{
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40025.json",
"cna_assigner": "VulnCheck"
}{
"cpe": "cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "4.15.0"
}
]
}"2026-07-27T09:24:28Z"
[
{
"signature_type": "Function",
"target": {
"file": "tsk/fs/apfs.cpp",
"function": "APFSKeybag::get_key"
},
"deprecated": false,
"source": "https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611",
"id": "CVE-2026-40025-0f9448fe",
"signature_version": "v1",
"digest": {
"function_hash": "64676707899275895585818978114147020768",
"length": 721.0
}
},
{
"signature_type": "Function",
"target": {
"file": "tsk/fs/apfs.cpp",
"function": "APFSFileSystem::init_crypto_info"
},
"deprecated": false,
"source": "https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611",
"id": "CVE-2026-40025-38dff4cd",
"signature_version": "v1",
"digest": {
"function_hash": "70860106093143932909002113358386148011",
"length": 2277.0
}
},
{
"signature_type": "Line",
"target": {
"file": "tsk/fs/tsk_apfs.hpp"
},
"deprecated": false,
"source": "https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611",
"id": "CVE-2026-40025-731aaac5",
"signature_version": "v1",
"digest": {
"line_hashes": [
"37442709601541052798385986290552953502",
"330927510266086804026411862520987195896",
"265256334558563411650241984127391742847",
"128127207950606374510166884818947191815",
"60300601898860241774149135517784200760",
"37936624773768353234005371727484133208",
"959709857445969514696018278871033734",
"214634036834192920441630090271407171215",
"124393334606449290637689122721506905060",
"101399933198801770788635357162510699462",
"147907001026773307721333262357934974623",
"231319378934227667040132396155225488988",
"59004572233820187235358873497281195622",
"48165441581517701210196598607498289125",
"111035410917538237416275652627685959993"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "tsk/fs/apfs.cpp",
"function": "APFSKeybag::get_keys"
},
"deprecated": false,
"source": "https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611",
"id": "CVE-2026-40025-ae2f908e",
"signature_version": "v1",
"digest": {
"function_hash": "250760894234121438644298776823776794828",
"length": 599.0
}
},
{
"signature_type": "Line",
"target": {
"file": "tsk/fs/apfs.cpp"
},
"deprecated": false,
"source": "https://github.com/sleuthkit/sleuthkit/commit/8b9c9e7d493bd68624f3b1a3963edd45c3ff7611",
"id": "CVE-2026-40025-c7dc84ef",
"signature_version": "v1",
"digest": {
"line_hashes": [
"44744225820494273369880977052167228261",
"180010761206456122236138658015084689392",
"161453428347210214231089686866503034307",
"21572244893218339400230498055414819554",
"336198626884608305243511958033320413510",
"41767613342464754023795775815528750427",
"238984329497279217678133891883350090249",
"1200754526259358260945358585210718560",
"115389981840537399986780610240560672597",
"217551021807021999764424498324325306905",
"27506872341352011404436529381244539172",
"203163587641978296069594618808316110565",
"271039927439895749350504403069447845139",
"117244831814786084052910525848357658900",
"19372117138359884362045940422287447378",
"278677445476748611473500501820995489193",
"278250128894720362209983302471143899700",
"199831459830172235185565741252710885593",
"37013995593185470514534241007342719291",
"190977131921202718114121948404910515634",
"214614100121332571942102360637723639096",
"3191927802976125608768968205127494069",
"71037076657905281452429628740993524474",
"324876657875692197432551497956369891880",
"53329671876317753096044388839930192793",
"243094771175642492497883813552006721265",
"132930741346614571257060579542209406965",
"209318891626891132407303122135886965817",
"323236925055601547390185518568183915097",
"291751628160302385920452952560025742230",
"122013124204030366207479160960530824837",
"126960158200876722898627114448441158011",
"265939483808143275831520586762212382019",
"71779912697480605916828320659384054577",
"253624769557016988580365828682420072773",
"174076266673209130548104760260465977698",
"109897709471083490354414593867530683585",
"138434616657635560091980470109674184431",
"216188185278704649898698487217397273459",
"239230328560481898629724076308003114336",
"219917262602936863014811460558092375446",
"198679787452635976405818557931482042723",
"282145444427506793112567483712630468032",
"220540907875251304657766866391113330436",
"222041839562780184884956574785612309256",
"241318206651622518168146412590371253342",
"108476234158927923328351102279703786394",
"191312174658110827119681483136242380799",
"47039940033356453741649139683607509680",
"145633968383706278433026439288519638592",
"149055279751284581105197710496243695122",
"262984209677934837496087688843683987144",
"297536184940427700511535542250282150853",
"161599721659678611685617849960553523850",
"300447280739090168781560499383220511365",
"180481262857623082665319941467544820756",
"109028383424286850382876106721502844132",
"34988862257584743656284184409382139471",
"208303685787090879902522660435288795629",
"270483471289629961197399830159679469779",
"273448191588493383581888515975733710427",
"161537006792173799429012808054013127404",
"44821822421323015426794226751515516389",
"261527915149566437005375164311017203620",
"39510200941079978873642955980447978264",
"54636436020523826476398328692125963773",
"5756248957323445813567586873357925753",
"337113119957916620307728926919119922161",
"196070942677259903122998198828237770371",
"79205893184857852306355773504511631797",
"123545156256320385558656657060790422021",
"100527977039555589565616549697434195131",
"203525146572969340923238720334657101021",
"127715142805339802069408731417506936846",
"114183752979334440243402184742992548928",
"305071326832422290213604443423951795257",
"225254968641268422031234968104127909729",
"204260172524095202571742313419448705078",
"25102529298056001258630535615961992562",
"251372105834751168860117090151897816226",
"207968418051447245158514267136311395920"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40025.json"