Seven Weaknesses in FatFs File System Component for...

runZero disclosed seven critical FatFs vulnerabilities (R0.16 and earlier) affecting millions of embedded devices, including USB drives, SD cards,

Event Description

On July 1, 2026, cybersecurity firm runZero, specializing in network exposure management, formally disclosed that the FatFs file system module (versions R0.16 and earlier), widely used in small embedded systems, contains seven critical security vulnerabilities. These vulnerabilities were discovered by runZero's founder and CEO HD Moore through deep investigation of FAT and exFAT parsing mechanisms. The CVSS severity scores for the vulnerabilities vary; CVE-2026-6682, CVE-2026-6687, and CVE-2026-6688 are rated as high-risk with CVSS scores up to 7.6; CVE-2026-6685 is medium-risk (6.1); while CVE-2026-6683, CVE-2026-6684, and CVE-2026-6686 are medium-risk (4.6)[6][2]. Notably, HD Moore attempted to contact FatFs maintainer ChaN in late April without success, sought coordination via JPCERT/CC but received no response, and ultimately communicated with major downstream vendors in mid-May before publicly disclosing the vulnerabilities on July 1[6].

Technical Analysis

FatFs is a general-purpose FAT/exFAT file system module designed for resource-constrained small MCUs, unrestricted by platform or storage device. Its core vulnerabilities involve memory corruption, integer overflow, logic errors, and information leakage. According to technical details, the most severe CVE-2026-6682 is an integer overflow located in the mount_volume() function, which may occur when executing fasize *= fs->n_fats, potentially causing value wrap and enabling attackers to tamper with file size metadata, leading to downstream exploitation[2][3]. Another high-risk vulnerability, CVE-2026-6687, is a stack overflow related to exFAT label handling, occurring in the f_getlabel() function, which may cause memory corruption or code execution[2]. Additionally, these vulnerabilities can be triggered via carefully crafted USB drives, SD cards, or mounted firmware update images, resulting in memory corruption, denial of service, silent data corruption, and potential code execution[2]. runZero's research team utilized Visual Studio Code, GitHub Copilot's automatic mode, and fuzzing tools to successfully discover trivial vulnerabilities missed by manual audits and verified their actual exploitability across various embedded scenarios[6].

Impact Scope

Since FatFs is widely "vended" (directly embedded) into multiple mainstream open-source ecosystems, its impact scope is extensive, covering consumer IoT devices, industrial controllers, drones, crypto wallets, and other products. Key affected ecosystems include: STMicroelectronics' STM32Cube middleware (STM32 is the MCU with the highest global market share), Espressif's ESP-IDF framework (ESP32 series has extremely high shipment volume), Zephyr RTOS (an open-source operating system led by the Linux Foundation), and ArduPilot (widely used in drones and autonomous driving devices)[2][6]. runZero warns that if attackers gain physical access to vulnerable devices (e.g., inserting malicious USB or SD cards), systems may be "jailbroken" or fully compromised in the absence of ASLR (Address Space Layout Randomization) and memory protection[6]. However, for general users with only brief access to devices (e.g., using network video cameras, voting machines, ATMs, or touchscreen devices), the risk is relatively low and does not lead to full system compromise[6]. The research team has released proof-of-concept images, test architectures, and QEMU-based exploitation examples; downstream vendors identifying and fixing their bundled versions may take several years[2].

Protection Recommendations

In the current situation lacking complete upstream patches (only CVE-2026-6684 is patched in FatFs R0.16, and CVE-2026-6683 has only partial protection), device vendors and users should adopt the following protective measures: First, strictly disable untrusted USB storage devices or SD cards, restrict access to untrusted FAT/exFAT media, and prevent automatic mounting of malicious images[1][6]. Second, disable unnecessary exFAT support, as some high-risk vulnerabilities (e.g., CVE-2026-6687) are directly related to exFAT label handling[2]. Third, downstream vendors should independently add additional checks and protection logic in their code, such as validating file size metadata to prevent integer overflow and strengthening stack protection to resist overflow attacks[1][2]. ReconShield Intelligence recommends enterprises execute three steps for detection and response and guides device vendors to take five steps to enhance security[6]. Due to the lack of coordination and maintainer response, proactive defense and downstream self-patching have become the key strategies currently.

5-Step Patch Checklist

  • Step 1: Immediately review and update all embedded systems integrating FatFs, confirm whether the version is R0.16 or higher, and check the patch status of CVE-2026-6684.
  • Step 2: Enforce disabling of all untrusted USB storage devices and SD cards in system policies to prevent automatic mounting of malicious FAT/exFAT media.
  • Step 3: Disable unnecessary exFAT support functionality in the system to eliminate high-risk vulnerabilities related to exFAT label handling, such as CVE-2026-6687.
  • Step 4: Downstream vendors should independently add additional input validation logic at the code level, especially performing overflow checks on integer multiplication operations in mount_volume().
  • Step 5: Implement memory protection mechanisms (such as ASLR and stack protection) and regularly monitor OSINT and threat intelligence to respond to potential physical access attacks.

References

  • Seven Weaknesses in FatFs File System Component for Small Embedded Devices
  • Seven FatFs Flaws Expose Embedded Devices to Malicious USB and SD Media
  • FatFsの欠陥により、組み込みデバイスが悪意のあるUSB ...
  • In FatFS R0.16 and earlier contains a FAT32 integer ...

More cybersecurity news