Bug 2458083 - CVE-2026-40024 sleuthkit: The Sleuth Kit: Arbitrary code execution via path traversal in tsk_recover [fedora-43]
Summary: CVE-2026-40024 sleuthkit: The Sleuth Kit: Arbitrary code execution via path t...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: sleuthkit
Version: 43
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Nicolas Chauvet (kwizart)
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["cb28e7cc-af22-462c-a2af-c...
Depends On:
Blocks: CVE-2026-40024
TreeView+ depends on / blocked
 
Reported: 2026-04-13 23:42 UTC by Praise Ogwuche
Modified: 2026-04-28 01:36 UTC (History)
2 users (show)

Fixed In Version: sleuthkit-4.15.0-2.fc43 sleuthkit-4.15.0-2.fc42 sleuthkit-4.15.0-2.el9 sleuthkit-4.15.0-2.el10_2 sleuthkit-4.15.0-2.el10_3 sleuthkit-4.15.0-2.fc44 sleuthkit-4.15.0-3.el8
Clone Of:
Environment:
Last Closed: 2026-04-28 00:57:27 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Praise Ogwuche 2026-04-13 23:42:11 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 1 Fedora Update System 2026-04-17 14:26:24 UTC
FEDORA-EPEL-2026-aa4ed82378 (sleuthkit-4.15.0-2.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-aa4ed82378

Comment 2 Fedora Update System 2026-04-17 14:26:47 UTC
FEDORA-EPEL-2026-dbd1189b1b (sleuthkit-4.15.0-3.el8) has been submitted as an update to Fedora EPEL 8.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-dbd1189b1b

Comment 3 Fedora Update System 2026-04-18 01:18:36 UTC
FEDORA-EPEL-2026-aa4ed82378 has been pushed to the Fedora EPEL 10.3 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-aa4ed82378

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 4 Fedora Update System 2026-04-18 01:25:07 UTC
FEDORA-EPEL-2026-dc1ada20f0 has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-dc1ada20f0

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-04-18 01:32:59 UTC
FEDORA-2026-fb92ac63e1 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-fb92ac63e1`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-fb92ac63e1

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-04-18 01:34:30 UTC
FEDORA-EPEL-2026-715736f2b5 has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-715736f2b5

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2026-04-18 01:52:08 UTC
FEDORA-EPEL-2026-dbd1189b1b has been pushed to the Fedora EPEL 8 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-dbd1189b1b

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2026-04-18 01:53:38 UTC
FEDORA-2026-41a87be616 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-41a87be616`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-41a87be616

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2026-04-18 02:18:09 UTC
FEDORA-2026-a781166270 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-a781166270`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-a781166270

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2026-04-28 00:57:27 UTC
FEDORA-2026-a781166270 (sleuthkit-4.15.0-2.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 11 Fedora Update System 2026-04-28 01:13:22 UTC
FEDORA-2026-41a87be616 (sleuthkit-4.15.0-2.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 12 Fedora Update System 2026-04-28 01:13:53 UTC
FEDORA-EPEL-2026-dc1ada20f0 (sleuthkit-4.15.0-2.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 13 Fedora Update System 2026-04-28 01:25:59 UTC
FEDORA-EPEL-2026-715736f2b5 (sleuthkit-4.15.0-2.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 14 Fedora Update System 2026-04-28 01:26:23 UTC
FEDORA-EPEL-2026-aa4ed82378 (sleuthkit-4.15.0-2.el10_3) has been pushed to the Fedora EPEL 10.3 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 15 Fedora Update System 2026-04-28 01:31:29 UTC
FEDORA-2026-fb92ac63e1 (sleuthkit-4.15.0-2.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 16 Fedora Update System 2026-04-28 01:36:19 UTC
FEDORA-EPEL-2026-dbd1189b1b (sleuthkit-4.15.0-3.el8) has been pushed to the Fedora EPEL 8 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.