4.6
CVE-2026-6686
- EPSS 0.38%
- Veröffentlicht 01.07.2026 13:55:09
- Zuletzt bearbeitet 02.07.2026 14:38:35
- CVE-Watchlists
- Unerledigt
FatFs Use of Uninitialized Clusters After Seek Past EOF
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.303 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 44488dab-36db-4358-99f9-bc116477f914 | 4.6 | 0.9 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-908 Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.runzero.com/blog/fatfs-bugs/
https://github.com/runZeroInc/vulns-2026-fatfs-chance
https://elm-chan.org/fsw/ff/
https://www.runzero.com/advisories/fatfs-uninit-cluster-exposure-cve-2026-6686/