Executive brief
FatFs is a widely used file system module for small embedded devices like IoT sensors, industrial controllers, and medical equipment. A flaw in how it handles data caching can lead to silent data corruption when reading or writing files on fragmented storage media (like SD cards or flash drives). An attacker with physical access to the device could use a specially crafted storage disk to cause the system to malfunction, log incorrect data, or execute unintended commands.
Technical details
An integer underflow (CWE-191) exists in the dirty-cache handling logic of f_read() and f_write(). The vulnerability occurs when the cached sector (fp->sect) is numerically lower than the current sector (sect), which is common on fragmented volumes. The subtraction 'fp->sect - sect' wraps to a large unsigned value, which may still satisfy the ' < cc' boundary check if the transfer count is large. This causes a memcpy to execute with an out-of-bounds offset, leading to stale data being written to the buffer or memory corruption. This is exploitable via physical access using fragmented media or by inducing fragmentation over time on long-lived devices.
Affected products
- ChaN FatFs R0.16 and earlier
Timeline
- 2026-06-30: advisory: runZero published detailed advisory
- 2026-07-01: disclosed: CVE published to NVD