logo

Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks

ID: 25caaa69-c287-5545-b588-842d565a30a0

STIX ID: report--25caaa69-c287-5545-b588-842d565a30a0

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-04

Date Updated: 2026-07-04

Author: Guru Baran

...
...

runZero disclosed seven newly assigned CVEs (CVSS 4.6–7.6) in FatFs, the lightweight FAT/exFAT filesystem driver used across many embedded and IoT ecosystems (ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot, etc.). The issues include integer overflows, uncapped label-length writes, LFN-related buffer overflows, unsigned-subtraction wraparounds (causing data corruption), divide-by-zero crashes, uninitialized data leaks, and GPT partition-scan DoS; several can be triggered by crafted media or auto-mounted update channels and may lead to code execution on devices lacking modern memory protections. runZero reports maintainers were unresponsive and warns downstream vendors to audit and patch vendored FatFs copies before deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.