CVE-2026-6682
Last modified
CVE-2026-6682 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound). EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). Remote delivery is also possible in OTA/update pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elm-Chan | Fatfs | <= r0.16 |
References
- https://elm-chan.org/fsw/ff/Product
- https://github.com/runZeroInc/vulns-2026-fatfs-chanceThird Party Advisory, Exploit
- https://www.runzero.com/advisories/fatfs-fat32-int-of-mnt-cve-2026-6682/Third Party Advisory, Exploit
- https://www.runzero.com/blog/fatfs-bugs/Third Party Advisory, Exploit
- https://github.com/runZeroInc/vulns-2026-fatfs-chanceThird Party Advisory, Exploit
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-6682?
How severe is CVE-2026-6682?
How do I fix CVE-2026-6682?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66806Off-by-one error in Microsoft Office Word allows an unauthor…5.5
- CVE-2026-66807Stack-based buffer overflow in Microsoft Office allows an un…7.8
- CVE-2026-66808Deserialization of untrusted data in Microsoft Office ShareP…8.8
- CVE-2026-66809Out-of-bounds read in Microsoft Office allows an unauthorize…5.5
- CVE-2026-6681The PKCS#7 decode path ignores the caller-supplied output bu…5.3
- CVE-2026-66810Heap-based buffer overflow in Microsoft Office Word allows a…5.5
- CVE-2026-66824A stored cross-site scripting vulnerability existed in the c…9.2
- CVE-2026-66825Pivotick contains a cross-site scripting vulnerability in th…6.9
- CVE-2026-66829URL Redirection to Untrusted Site ('Open Redirect') vulnerab…6.1
- CVE-2026-6683FatFs R0.16 and earlier contains a divide-by-zero in exFAT s…4.6
- CVE-2026-66832When the Mira Android app opens in-app WebView content (e.g.…6.9
- CVE-2026-66838Improper Neutralization of Special Elements used in an SQL C…5.9
Are you affected by CVE-2026-6682?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
