Heap-based buffer overflow in the verifyvbrchecksum function in exfatfsck in exfat-utils before 1.2.1 allows remote attackers to cause a denial of service (infinite loop) or possibly execute arbitrary code via a crafted filesystem.
exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in readfiledentryset.
relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in certain situations involving offsets beyond ValidDataLength.