Files
fatfs/source
Christopher Williams dbd6192332 R0.16 patch 3
July 10, 2026

Some vulnerabilities in FatFs R0.16 and earlier have been found and published.

CVE-2026-6682 (*)
A FAT BPB with broken FAT size field can collapse the files or lead a system crash.

CVE-2026-6687 (*)
An exFAT volume label with manipulated name length field can lead a buffer overflow.

CVE-2026-6688
LFN length is 255 UTF-16 encode units maximum. Please make sure the size of buffer is sufficient
to copy the read file name.

CVE-2026-6685
Wraparound in these expressions are intentional and not harmful.

CVE-2026-6683 (*)
An exFAT BPB with manipulated cluster count field can trigger a /0 and lead the system crash.

CVE-2026-6686
This behavior has been documented in the manual. Please be careful.

CVE-2026-6684
A manipulated table size field in GPT header can lead the system freeze. It does not cover FatFs R0.16.

This publishment of problems was reported via an SNS.
2026-07-09 16:42:23 -07:00
..
2025-07-21 16:32:22 -07:00
2025-07-21 16:32:22 -07:00
2026-07-09 16:42:23 -07:00
2025-07-21 16:32:22 -07:00
2025-07-21 16:32:22 -07:00
2025-08-04 16:35:49 -07:00