CVE-2026-6683Disclosure(elm-chan / fatfs)

LOWCVSS 4.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch elm-chan fatfs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-369

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fatfs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fatfs

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-04: 1Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-04: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-07-04: 107-0407-06
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Classification over time
DateTotalLabels
2026-07-041
Disclosure1
2026-07-061
General1
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Siber güvenlik şirketi runZero tarafından, yaygın olarak kullanılan FatFs dosya sistemi kütüphanesinde 7 güvenlik açığı tespit edildi. Güvenlik kameraları, IoT cihazları, dronlar ve birçok gömülü sistem potansiyel olarak etkilenebilir. En kritik açık CVE-2026-6682 (CVSS 7.6), özel hazırlanmış FAT32/exFAT medya üzerinden bellek bozulmasına (memory corruption) ve bazı senaryolarda uzaktan kod çalıştırmaya (RCE) yol açabiliyor. Tespit edilen CVE'ler: • CVE-2026-6682 – Integer overflow → Memory corruption / RCE • CVE-2026-6683 – exFAT divide-by-zero (DoS) • CVE-2026-6684 – Bozuk GPT partition tablosu ile DoS • CVE-2026-6685 – Cache hesaplama hatası, veri bozulması • CVE-2026-6686 – Bilgi sızıntısı • CVE-2026-6687 – exFAT volume label buffer overflow • CVE-2026-6688 – Long File Name (LFN) buffer overflow Şu ana kadar aktif istismar raporlanmadı. Ancak PoC'ler genele açık durumda. FAT/FAT32/exFAT kullanan gömülü sistem geliştiren üreticilerin FatFs entegrasyonlarını gözden geçirerek gerekli güvenlik güncellemelerini yayınlaması önem taşıyor.

    Post summary

    RunZero has disclosed seven CVEs in FatFs, including a critical RCE and several DoS flaws; PoCs are publicly available but no active exploitation has been reported, prompting vendors to release updates.

    01072828
    2.2K followersView on X
  • Philips_NE555@Philips_NE555
    General

    CVE-2026-6685 CVE-2026-6683 I couldn't find the condition to trigger these bugs but it might lead the system crash.

    Post summary

    The text merely lists CVE identifiers and expresses uncertainty about triggering them, providing no substantive technical or operational details.

    10000114
    2.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelm-chanfatfs---

Explore more