ChaN FatFs是ChaN公司的一个为嵌入式系统设计的通用 FAT/exFAT 文件系统模块。 ChaN FatFs R0.16及之前版本存在数字错误漏洞,该漏洞源于mount_volume()函数中存在FAT32整数溢出错误,导致fasize *= fs->n_fats可能发生环绕,从而允许攻击者控制文件大小元数据,并在下游调用者中造成不安全的读取长度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-6688 | 7.6 HIGH | FatFs Buffer Overflow via Unbounded LFN Filename Copy |
| CVE-2026-6687 | 7.6 HIGH | FatFs Stack Buffer Overflow via Uncapped exFAT Label Length |
| CVE-2026-6684 | 4.6 MEDIUM | FatFs Infinite Loop in GPT Partition Scan |
| CVE-2026-6686 | 4.6 MEDIUM | FatFs Use of Uninitialized Clusters After Seek Past EOF |
| CVE-2026-6683 | 4.6 MEDIUM | FatFs Divide-by-Zero in exFAT Sync |
No comments yet