diff --git a/components/fatfs/sbom.yml b/components/fatfs/sbom.yml index 6c994059fbb..6a11a9eddda 100644 --- a/components/fatfs/sbom.yml +++ b/components/fatfs/sbom.yml @@ -10,3 +10,5 @@ cve-exclude-list: reason: exFAT divide-by-zero when NumClusters == 0. The vulnerable exFAT PercInUse sync division was introduced in R0.16 and is not present in this R0.15 release; an empty cluster heap is additionally rejected at mount as defense-in-depth. - cve: CVE-2026-6685 reason: Unsigned-subtraction wrap in the dirty-cache refill check. Patched by requiring the cached sector to lie within the direct-I/O range in both f_write() and f_read(). + - cve: CVE-2026-6687 + reason: exFAT label-length overflow in f_getlabel(). Patched by clamping XDIR_NumLabel to the 11-unit exFAT label maximum. diff --git a/components/fatfs/src/ff.c b/components/fatfs/src/ff.c index 77a88e18fde..9d1a2ab5b2d 100644 --- a/components/fatfs/src/ff.c +++ b/components/fatfs/src/ff.c @@ -5411,9 +5411,11 @@ FRESULT f_getlabel ( #if FF_FS_EXFAT if (fs->fs_type == FS_EXFAT) { WCHAR hs; - UINT nw; + UINT nw, nchar; - for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++) { /* Extract volume label from 83 entry */ + nchar = dj.dir[XDIR_NumLabel]; /* Number of UTF-16 characters in the label entry */ + if (nchar > 11) nchar = 11; /* CVE-2026-6687: clamp to the exFAT maximum (11) to prevent OOB read of the entry and overflow of the caller label buffer */ + for (si = di = hs = 0; si < nchar; si++) { /* Extract volume label from 83 entry */ wc = ld_word(dj.dir + XDIR_Label + si * 2); if (hs == 0 && IsSurrogate(wc)) { /* Is the code a surrogate? */ hs = wc; continue;