Executive brief
FatFs is a widely used software library that allows small embedded devices, such as IoT sensors and industrial controllers, to read and write data to SD cards and USB drives. A vulnerability exists in how the library handles long filenames, which can cause the software to crash or allow unauthorized code execution when a specially crafted storage device is inserted. This flaw impacts a broad range of downstream products including the Zephyr RTOS, Samsung TizenRT, and various firmware for CNC machines and drones.
Technical details
A buffer overflow vulnerability (CWE-120) exists in the integration patterns of ChaN FatFs R0.16 and earlier. When Long Filename (LFN) support is enabled, the 'fno.fname' field can contain up to 255 characters, but many downstream callers allocate buffers based on the shorter 8.3 filename standard (typically ~13-14 bytes). Attackers can exploit this by providing a FAT-formatted storage medium containing crafted long filenames, which triggers overflows in functions like strcpy() or sprintf() within the calling application. This pattern has been identified in multiple major embedded projects, including Zephyr RTOS, NodeMCU, and TizenRT. Exploitation requires physical access to insert the malicious media but can result in total system compromise.
Affected products
- ChaN FatFs R0.16 and earlier
Timeline
- 2026-06-30: advisory: Initial advisory published by runZero
- 2026-07-01: disclosed: CVE-2026-6688 published