ChaN FatFs是ChaN公司的一个为嵌入式系统设计的通用 FAT/exFAT 文件系统模块。 ChaN FatFs R0.16及之前版本存在缓冲区错误漏洞,该漏洞源于FatFs长文件名处理中存在下游调用者漏洞模式,启用LFN时,fno.fname最多可达255个字符,许多调用者将其复制到没有边界检查的短固定缓冲区中,导致缓冲区溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-6687 | 7.6 HIGH | FatFs Stack Buffer Overflow via Uncapped exFAT Label Length |
| CVE-2026-6682 | 7.6 HIGH | FatFs Integer Overflow in FAT32 Volume Mount |
| CVE-2026-6684 | 4.6 MEDIUM | FatFs Infinite Loop in GPT Partition Scan |
| CVE-2026-6686 | 4.6 MEDIUM | FatFs Use of Uninitialized Clusters After Seek Past EOF |
| CVE-2026-6683 | 4.6 MEDIUM | FatFs Divide-by-Zero in exFAT Sync |
No comments yet