Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks
ID: 25caaa69-c287-5545-b588-842d565a30a0
STIX ID: report--25caaa69-c287-5545-b588-842d565a30a0
Feed Name: cybersecurityNews.com
runZero disclosed seven newly assigned CVEs (CVSS 4.6–7.6) in FatFs, the lightweight FAT/exFAT filesystem driver used across many embedded and IoT ecosystems (ESP-IDF, STM32Cube, Zephyr, MicroPython, ArduPilot, etc.). The issues include integer overflows, uncapped label-length writes, LFN-related buffer overflows, unsigned-subtraction wraparounds (causing data corruption), divide-by-zero crashes, uninitialized data leaks, and GPT partition-scan DoS; several can be triggered by crafted media or auto-mounted update channels and may lead to code execution on devices lacking modern memory protections. runZero reports maintainers were unresponsive and warns downstream vendors to audit and patch vendored FatFs copies before deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
