Executive brief
FatFs is a widely used software library that allows small embedded devices, such as industrial controllers and consumer electronics, to read files from storage media like SD cards. A flaw in how the library handles certain partition data allows a specially crafted storage device to cause the system to hang indefinitely during startup. This can result in a permanent denial of service, preventing the device from booting or functioning until the malicious storage media is removed or the firmware is recovered.
Technical details
A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in FatFs prior to version R0.16 when configured with 'FF_LBA64 = 1'. The issue stems from the GPT partition scanning logic, which trusts the partition-entry count (GPTH_PtNum) provided by the on-disk GPT header without sufficient validation or hard caps. An attacker with physical access can provide a crafted GPT image with a maximized partition count (e.g., 0xFFFFFFFF), forcing the library into a massive read loop during the mount process. This typically results in a system hang or boot failure, especially on bare-metal targets lacking a watchdog timer. The issue was addressed in R0.16 by adding the test_gpt_header() function to validate partition counts and CRCs.
Affected products
- ChaN FatFs Prior to R0.16 with FF_LBA64 = 1 enabled
Timeline
- 2026-03-17: disclosed: Initial findings discovered by runZero researchers
- 2026-07-01: advisory: NVD publication date