Back Feeds.4Sysops Seven unpatched FatFs vulnerabilities expose millions of embedded devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a widely used filesystem library that enables devices to read and write FAT and exFAT formats on USB drives and SD cards. The flaws affect FAT, exFAT, and GPT parsing, and they can be triggered by malicious media or mounted firmware images. Exploitation can lead to memory corruption, denial of service, information disclosure, silent data corruption, and potential code execution. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
