Executive brief
FatFs is a widely used software library that allows small embedded devices, such as industrial controllers and consumer electronics, to read and write to SD cards and USB drives. A flaw in how it handles specific storage formats (exFAT) allows a maliciously prepared memory card to crash the device as soon as it tries to save data. This can lead to permanent equipment failure or 'bricking' if the crash occurs during a critical system update.
Technical details
A divide-by-zero vulnerability (CWE-369) exists in the exFAT free-space accounting logic within the sync_fs() function. When a crafted exFAT volume sets the BPB_NumClusEx field to zero, the internal variable n_fatent collapses to 2, resulting in a division by zero during arithmetic operations used to calculate cluster usage percentages. The vulnerability is triggered during f_write, f_sync, or f_close operations on the affected volume. This leads to a processor hard fault or SIGFPE, causing a denial of service. While primarily a physical attack vector via malicious media, it may be reachable remotely in systems that process network-delivered disk images or OTA updates.
Affected products
- ChaN FatFs R0.16 and earlier
Timeline
- 2026-07-01: disclosed: Vulnerability published in NVD and by runZero research team.