CVE-2020-10232: Debian Linux

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
  • Sleuthkit The Sleuth Kit: up to and including 4.8.0

Published 2020-03-09. Last modified 2026-06-17.