top of page
perceptive_background_267k.jpg

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. Thi…

Published:

30 juni 2026 om 22:00:00

Alert date:

1 juli 2026 om 19:17:24

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure, Zero-Day Vulnerabilities

FatFs R0.16 and earlier versions contain a stack-based buffer overflow vulnerability in the f_getlabel() function. The flaw arises because the exFAT label length field (XDIR_NumLabel) is trusted without enforcing the specification's maximum limits, allowing an attacker to trigger a stack overflow. This vulnerability is classified as CWE-121 (Stack-based Buffer Overflow). The CVSS v3.1 score is 7.6 (High), with physical access required (AV:P) but no privileges or user interaction needed. The scope is changed with high impact across confidentiality, integrity, and availability. A proof-of-concept exploit exists, and CISA SSVC rates the technical impact as Total. Affected systems include any embedded or application using FatFs for exFAT filesystem support.

Technical details

Mitigation steps:

Affected products:

FatFs R0.16
FatFs

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page