PT-2026-2128 · Cryptolib · Cryptolib

Finder16

·

Publicado

2026-01-10

·

Atualizado

2026-01-15

·

CVE-2026-21898

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution that uses the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. Prior to version 1.4.3, the Crypto AOS ProcessSecurity function does not perform valid bounds checking when parsing AOS frame hashes, leading to a potential issue.
Recommendations Versions prior to 1.4.3 should be updated to version 1.4.3 or later.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21898
GHSA-7CH6-2PMG-M853

Produtos afetados

Cryptolib