This release addresses an out-of-bounds write in fault-tolerant log replay, completes Windows simulator support with native Win32 and Win64 ports, and puts FileX's regression suite behind real gates for the first time — nine Linux coverage configurations and a Win64 job, running on dev as well as master.
We thank contributors from STMicroelectronics, along with the independent contributor @adawn0106, for their valuable contributions to this release.
Vulnerabilities Addressed
- CVE-2026-91041 (7.8 High, CWE-787, CWE-1284)
FileX fault-tolerant log replay writes past the destination sector when mounting a crafted FAT image
A directory log entry names the offset and the size of a copy into a single sector staged in the media's memory buffer. Both values come off the media, and the replay path bounded them against the whole cache allocation rather than against the sector, so mounting a crafted image could write past the destination sector. Enabling fault tolerance also accepted a recorded log size larger than the buffer the caller supplied.
Affects 6.0.1 through 6.5.1.202602 inclusive, fixed in 6.5.2.202603. Reported by @adawn0106; fixed by @rahmanih and @fdesbiens. The fix ships with a regression test that fails when any one of its four bounds is reverted on its own.
You can access advisories for previously addressed vulnerabilities here.
Highlights
Windows simulator support
FileX now has native Win32 and Win64 simulator ports, built with the Visual Studio 2019 and 2022 toolchains, and the regression suite runs against both. (#94, #100, @fdesbiens)
Getting the suite to pass on Windows took more than a port. The large-media tests allocate roughly 1.7 GB of RAM disk and data buffers, which overflows the default 2 GB address space of a 32-bit process, so the Win32 executables are linked /LARGEADDRESSAWARE. On MSVC those buffers are heap-allocated rather than committed to BSS, which would otherwise exceed the 2 GB image limit. Test target names are hashed on MSVC because several descriptive FileX test names exceed the legacy path limit once CMake nests its object directories.
Regression gates
The regression workflow now runs on dev as well as master, builds and tests all nine Linux coverage configurations rather than a subset, and adds a Win64 job. Coverage is collected from every configuration, merged, and gated. Pages deploys only after a successful master run. (#106, @fdesbiens)
ThreadX is pinned by commit rather than cloned from a floating branch, and the runner refuses to build against a checkout that does not match. Previously a run validated FileX against whatever ThreadX's default branch held that day, never recorded which commit that was, and silently reused an existing clone however old it had become.
Deprecations
Six FileX APIs are flagged as deprecated. (#95, #101, @fdesbiens)
A note for anyone reading the Windows ports' version
The Win32 and Win64 ports reported FileX Win64/Visual 6.5.1.202602 at run time, with no Version between the port name and the number. The release script keys on that word, so neither port had ever been reached by a version pass. Both now report 6.5.2.202603 correctly. (#114, @fdesbiens)
Other Changes
- Added a regression test covering the fault-tolerant log bounds that the advisory fix left half-tested, so each of its four guards now fails the suite when reverted alone (#111, @fdesbiens)
- Added a check that keeps the AI disclosure comment in its one accepted form (#103, @fdesbiens)
- Updated the contribution guide for the current build, test and submission workflows (#107, @fdesbiens)
- Linked readers to the published documentation rather than the archived site (#105, @fdesbiens)
- Updated the security policy (#96, @fdesbiens)
- Added a blame ignore list so the mechanical header and version passes no longer mask authorship (#102, @fdesbiens)
- Stopped the release script adding a
Co-authored-bytrailer, which asserts an authorship an AI cannot hold (#108, @fdesbiens) - Stopped the version pass skipping ports in silence: a port whose version string is shaped unexpectedly is now named and the pass stops, rather than keeping its old release while the pass reports success (#113, @fdesbiens)
New Contributors
- @rahmanih made their first contribution in the fix for CVE-2026-91041
Full Changelog: v6.5.1.202602_rel...v6.5.2.202603_rel