Junglewise Threat Intelligence

CVE-2026-6684: ChaN FatFs infinite loop in GPT partition scanning

CVE-2026-6684 · Severity: medium · CVSS 4.6 · Published 2026-07-01

Technologies: ChaN FatFs. Vendors: ChaN.

Executive brief

FatFs is a widely used software library that allows small embedded devices, such as industrial controllers and consumer electronics, to read files from storage media like SD cards. A flaw in how the library handles certain partition data allows a specially crafted storage device to cause the system to hang indefinitely during startup. This can result in a permanent denial of service, preventing the device from booting or functioning until the malicious storage media is removed or the firmware is recovered.

Technical details

A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in FatFs prior to version R0.16 when configured with 'FF_LBA64 = 1'. The issue stems from the GPT partition scanning logic, which trusts the partition-entry count (GPTH_PtNum) provided by the on-disk GPT header without sufficient validation or hard caps. An attacker with physical access can provide a crafted GPT image with a maximized partition count (e.g., 0xFFFFFFFF), forcing the library into a massive read loop during the mount process. This typically results in a system hang or boot failure, especially on bare-metal targets lacking a watchdog timer. The issue was addressed in R0.16 by adding the test_gpt_header() function to validate partition counts and CRCs.

Affected products

  • ChaN FatFs Prior to R0.16 with FF_LBA64 = 1 enabled

Timeline

  • 2026-03-17: disclosed: Initial findings discovered by runZero researchers
  • 2026-07-01: advisory: NVD publication date

References

Related threats