PT-2026-2133 · Cryptolib · Cryptolib
Enitmar
+1
·
Publicado
2026-01-10
·
Atualizado
2026-01-10
·
CVE-2026-22025
CVSS v4.0
6.3
Média
| Vetor | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CryptoLib versions prior to 1.4.3
Description
CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. Before version 1.4.3, the
cryptography encrypt() and cryptography decrypt() functions do not free allocated buffers when the KMC server returns a non-200 HTTP status code. Each failed request results in a memory leak of approximately 467 bytes, potentially leading to memory exhaustion with repeated failures. The issue occurs when interacting with the KMC server.Recommendations
Update to CryptoLib version 1.4.3 or later.
Exploit
Correção
Memory Leak
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cryptolib