Junglewise Threat Intelligence

CVE-2026-6683: ChaN FatFs divide by zero in exFAT sync logic

CVE-2026-6683 · Severity: medium · CVSS 4.6 · Published 2026-07-01

Technologies: ChaN FatFs. Vendors: ChaN.

Executive brief

FatFs is a widely used software library that allows small embedded devices, such as industrial controllers and consumer electronics, to read and write to SD cards and USB drives. A flaw in how it handles specific storage formats (exFAT) allows a maliciously prepared memory card to crash the device as soon as it tries to save data. This can lead to permanent equipment failure or 'bricking' if the crash occurs during a critical system update.

Technical details

A divide-by-zero vulnerability (CWE-369) exists in the exFAT free-space accounting logic within the sync_fs() function. When a crafted exFAT volume sets the BPB_NumClusEx field to zero, the internal variable n_fatent collapses to 2, resulting in a division by zero during arithmetic operations used to calculate cluster usage percentages. The vulnerability is triggered during f_write, f_sync, or f_close operations on the affected volume. This leads to a processor hard fault or SIGFPE, causing a denial of service. While primarily a physical attack vector via malicious media, it may be reachable remotely in systems that process network-delivered disk images or OTA updates.

Affected products

  • ChaN FatFs R0.16 and earlier

Timeline

  • 2026-07-01: disclosed: Vulnerability published in NVD and by runZero research team.

References

Related threats