4.6
CVE-2026-6684
- EPSS 0.43%
- Veröffentlicht 01.07.2026 13:45:03
- Zuletzt bearbeitet 02.07.2026 14:38:25
- CVE-Watchlists
- Unerledigt
FatFs Infinite Loop in GPT Partition Scan
FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.351 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 44488dab-36db-4358-99f9-bc116477f914 | 4.6 | 0.9 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.runzero.com/blog/fatfs-bugs/
https://github.com/runZeroInc/vulns-2026-fatfs-chance
https://elm-chan.org/fsw/ff/
https://www.runzero.com/advisories/fatfs-gpt-scan-loop-dos-cve-2026-6684/