7.6

CVE-2026-6687

Medienbericht
Exploit

FatFs Stack Buffer Overflow via Uncapped exFAT Label Length

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. This maps to CWE-121 (Stack-based Buffer Overflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Elm-chanFatfs Version <= r0.16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.373
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
44488dab-36db-4358-99f9-bc116477f914 7.6 0.9 6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
06.07.2026 15:32
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
03.07.2026 23:46
https://www.runzero.com/blog/fatfs-bugs/
Third Party Advisory
Exploit
https://github.com/runZeroInc/vulns-2026-fatfs-chance
Third Party Advisory
Exploit
https://elm-chan.org/fsw/ff/
Product
https://www.runzero.com/advisories/fatfs-exfat-label-len-of-cve-2026-6687/
Third Party Advisory