CVE-2017-13756: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Sleuthkit The Sleuth Kit: version 4.4.2 only

Published 2017-08-29. Last modified 2026-06-17.