PT-2026-2134 · Cryptolib+1 · Cryptolib+1

Enitmar

+1

·

Publicado

2026-01-10

·

Atualizado

2026-01-10

·

CVE-2026-22026

CVSS v4.0

8.2

Alta

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) for secure communication between a spacecraft and a ground station. The write callback function within the KMC crypto service client, prior to version 1.4.3, does not adequately limit the size of reallocated response buffers. This allows a malicious KMC server to send arbitrarily large HTTP responses, leading to excessive memory allocation and potential process termination. The vulnerable component is the libcurl function used for handling HTTP responses. The write callback function is specifically affected.
Recommendations Versions prior to 1.4.3 should be updated to version 1.4.3 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22026
GHSA-W9CM-Q69W-34X7

Produtos afetados

Cryptolib
Libcurl