dbd6192332
July 10, 2026 Some vulnerabilities in FatFs R0.16 and earlier have been found and published. CVE-2026-6682 (*) A FAT BPB with broken FAT size field can collapse the files or lead a system crash. CVE-2026-6687 (*) An exFAT volume label with manipulated name length field can lead a buffer overflow. CVE-2026-6688 LFN length is 255 UTF-16 encode units maximum. Please make sure the size of buffer is sufficient to copy the read file name. CVE-2026-6685 Wraparound in these expressions are intentional and not harmful. CVE-2026-6683 (*) An exFAT BPB with manipulated cluster count field can trigger a /0 and lead the system crash. CVE-2026-6686 This behavior has been documented in the manual. Please be careful. CVE-2026-6684 A manipulated table size field in GPT header can lead the system freeze. It does not cover FatFs R0.16. This publishment of problems was reported via an SNS.