CVE-2026-6687Disclosure(elm-chan / fatfs)

LOWCVSS 7.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch elm-chan fatfs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. This maps to CWE-121 (Stack-based Buffer Overflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fatfs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-04); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
fatfs

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-07-04: 2Mentions · 2026-07-06: 2PoC Mentioned / Linked · 2026-07-04: 2Patch / Workaround · 2026-07-04: 2Technical Details · 2026-07-04: 2Technical Details · 2026-07-06: 107-0407-06
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-042
Disclosure2
2026-07-062
General2
Full discourse4 posts
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🚨 Siber güvenlik şirketi runZero tarafından, yaygın olarak kullanılan FatFs dosya sistemi kütüphanesinde 7 güvenlik açığı tespit edildi. Güvenlik kameraları, IoT cihazları, dronlar ve birçok gömülü sistem potansiyel olarak etkilenebilir. En kritik açık CVE-2026-6682 (CVSS 7.6), özel hazırlanmış FAT32/exFAT medya üzerinden bellek bozulmasına (memory corruption) ve bazı senaryolarda uzaktan kod çalıştırmaya (RCE) yol açabiliyor. Tespit edilen CVE'ler: • CVE-2026-6682 – Integer overflow → Memory corruption / RCE • CVE-2026-6683 – exFAT divide-by-zero (DoS) • CVE-2026-6684 – Bozuk GPT partition tablosu ile DoS • CVE-2026-6685 – Cache hesaplama hatası, veri bozulması • CVE-2026-6686 – Bilgi sızıntısı • CVE-2026-6687 – exFAT volume label buffer overflow • CVE-2026-6688 – Long File Name (LFN) buffer overflow Şu ana kadar aktif istismar raporlanmadı. Ancak PoC'ler genele açık durumda. FAT/FAT32/exFAT kullanan gömülü sistem geliştiren üreticilerin FatFs entegrasyonlarını gözden geçirerek gerekli güvenlik güncellemelerini yayınlaması önem taşıyor.

    Post summary

    runZero reports seven new CVEs in FatFs used by embedded devices, including a critical RCE, with PoCs publicly available and no active exploitation yet; vendors are urged to release updates.

    01072828
    2.2K followersView on X
  • Philips_NE555@Philips_NE555
    General

    Theoe vulnerabilities in FatFs can be negligible except CVE-2026-6687.

    Post summary

    The statement notes that CVE‑2026‑6687 in FatFs is notable, but offers no further technical insight, exploit details, or remediation guidance.

    11043619
    2.4K followersView on X
  • Philips_NE555@Philips_NE555
    General

    CVE-2026-6687 Really dangerous! It can lead the system a buffer overflow.

    Post summary

    The text briefly notes that CVE-2026-6687 involves a buffer overflow, but provides no further details, PoC, exploit code, or patch information.

    11000295
    2.4K followersView on X
  • SecureChap@SecureChap
    Disclosure

    FatFs, the FAT12/16/32 and exFAT driver inside millions of cameras, drones, and crypto wallets, carried seven CVEs. runZero disclosed CVE-2026-6682 through CVE-2026-6688 on July 1, 2026 after contacting the single maintainer and JPCERT/CC with no upstream fix for six of them. Only CVE-2026-6684, a GPT partition DoS, was patched in R0.16. CVE-2026-6682 lets an attacker-controlled file size from FAT32 mount arithmetic become a read length, producing memory corruption. CVE-2026-6687 overflows the stack via an uncapped exFAT volume-label length. CVE-2026-6688 hits fixed buffers in downstream wrappers that copy long filenames with strcpy or undersized sprintf calls. A malformed disk image delivered by USB, SD card, or OTA update is enough. Espressif ESP-IDF, STM32Cube, Zephyr, MicroPython, and ArduPilot are among the platforms that ship it. Memory-constrained targets lack ASLR or any memory protection. The bugs survived a 2017 manual audit. In March 2026 they reappeared when Visual Studio Code with GitHub Copilot drove a basic fuzzer. PoCs and disk images are at http://github.com/runZeroInc/vulns-2026-fatfs-chance. One developer's filesystem quietly became the storage layer for entire classes of connected hardware.

    Post summary

    runZero disclosed seven FatFs CVEs with detailed technical descriptions and PoC disk images available, though only one was patched; no active exploitation is reported.

    0000084
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelm-chanfatfs---

Explore more