


Perceptive Security
SOC/SIEM Consultancy

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. Thi…
Published:
30 juni 2026 om 22:00:00
Alert date:
1 juli 2026 om 19:17:24
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure, Zero-Day Vulnerabilities
FatFs R0.16 and earlier versions contain a stack-based buffer overflow vulnerability in the f_getlabel() function. The flaw arises because the exFAT label length field (XDIR_NumLabel) is trusted without enforcing the specification's maximum limits, allowing an attacker to trigger a stack overflow. This vulnerability is classified as CWE-121 (Stack-based Buffer Overflow). The CVSS v3.1 score is 7.6 (High), with physical access required (AV:P) but no privileges or user interaction needed. The scope is changed with high impact across confidentiality, integrity, and availability. A proof-of-concept exploit exists, and CISA SSVC rates the technical impact as Total. Affected systems include any embedded or application using FatFs for exFAT filesystem support.
Technical details
Mitigation steps:
Affected products:
FatFs R0.16
FatFs
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6687
https://elm-chan.org/fsw/ff/
https://github.com/runZeroInc/vulns-2026-fatfs-chance
https://www.runzero.com/advisories/fatfs-exfat-label-len-of-cve-2026-6687/
https://www.runzero.com/blog/fatfs-bugs/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
