PT-2026-2133 · Cryptolib · Cryptolib

Enitmar

+1

·

Publicado

2026-01-10

·

Atualizado

2026-01-10

·

CVE-2026-22025

CVSS v4.0

6.3

Média

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. Before version 1.4.3, the cryptography encrypt() and cryptography decrypt() functions do not free allocated buffers when the KMC server returns a non-200 HTTP status code. Each failed request results in a memory leak of approximately 467 bytes, potentially leading to memory exhaustion with repeated failures. The issue occurs when interacting with the KMC server.
Recommendations Update to CryptoLib version 1.4.3 or later.

Exploit

Correção

Memory Leak

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22025
GHSA-H74X-VWWR-MM5G

Produtos afetados

Cryptolib