CVE-2026-6684Disclosure(elm-chan / fatfs)

MEDIUMCVSS 4.6 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch elm-chan fatfs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fatfs

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-04); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
fatfs

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-04: 2Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-04: 2Exploit Tool / Code · 2026-07-04: 1Patch / Workaround · 2026-07-04: 2Technical Details · 2026-07-04: 207-0407-06
Signal classification3 categories
Disclosure
133.3%
PoC
133.3%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-042
Disclosure1PoC1
2026-07-061
General1
Full discourse3 posts
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🚨 Siber güvenlik şirketi runZero tarafından, yaygın olarak kullanılan FatFs dosya sistemi kütüphanesinde 7 güvenlik açığı tespit edildi. Güvenlik kameraları, IoT cihazları, dronlar ve birçok gömülü sistem potansiyel olarak etkilenebilir. En kritik açık CVE-2026-6682 (CVSS 7.6), özel hazırlanmış FAT32/exFAT medya üzerinden bellek bozulmasına (memory corruption) ve bazı senaryolarda uzaktan kod çalıştırmaya (RCE) yol açabiliyor. Tespit edilen CVE'ler: • CVE-2026-6682 – Integer overflow → Memory corruption / RCE • CVE-2026-6683 – exFAT divide-by-zero (DoS) • CVE-2026-6684 – Bozuk GPT partition tablosu ile DoS • CVE-2026-6685 – Cache hesaplama hatası, veri bozulması • CVE-2026-6686 – Bilgi sızıntısı • CVE-2026-6687 – exFAT volume label buffer overflow • CVE-2026-6688 – Long File Name (LFN) buffer overflow Şu ana kadar aktif istismar raporlanmadı. Ancak PoC'ler genele açık durumda. FAT/FAT32/exFAT kullanan gömülü sistem geliştiren üreticilerin FatFs entegrasyonlarını gözden geçirerek gerekli güvenlik güncellemelerini yayınlaması önem taşıyor.

    Post summary

    runZero identified multiple CVEs in FatFs with publicly available PoCs; no active exploitation yet, but vendors are urged to patch the affected systems.

    01072828
    2.2K followersView on X
  • Philips_NE555@Philips_NE555
    General

    CVE-2026-6684 Doesn't cover the latest release.

    Post summary

    The short statement indicates that CVE-2026-6684 is not included in the latest release, but no further technical or exploit information is provided.

    10000178
    2.4K followersView on X
  • SecureChap@SecureChap
    Disclosure

    FatFs, the FAT12/16/32 and exFAT driver inside millions of cameras, drones, and crypto wallets, carried seven CVEs. runZero disclosed CVE-2026-6682 through CVE-2026-6688 on July 1, 2026 after contacting the single maintainer and JPCERT/CC with no upstream fix for six of them. Only CVE-2026-6684, a GPT partition DoS, was patched in R0.16. CVE-2026-6682 lets an attacker-controlled file size from FAT32 mount arithmetic become a read length, producing memory corruption. CVE-2026-6687 overflows the stack via an uncapped exFAT volume-label length. CVE-2026-6688 hits fixed buffers in downstream wrappers that copy long filenames with strcpy or undersized sprintf calls. A malformed disk image delivered by USB, SD card, or OTA update is enough. Espressif ESP-IDF, STM32Cube, Zephyr, MicroPython, and ArduPilot are among the platforms that ship it. Memory-constrained targets lack ASLR or any memory protection. The bugs survived a 2017 manual audit. In March 2026 they reappeared when Visual Studio Code with GitHub Copilot drove a basic fuzzer. PoCs and disk images are at http://github.com/runZeroInc/vulns-2026-fatfs-chance. One developer's filesystem quietly became the storage layer for entire classes of connected hardware.

    Post summary

    runZero disclosed seven CVEs in the FatFs driver, providing technical details and PoCs, noting one patch, but no evidence of active exploitation.

    0000084
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelm-chanfatfs---

Explore more