PT-2026-2128 · Cryptolib · Cryptolib

Finder16

·

Published

2026-01-10

·

Updated

2026-01-15

·

CVE-2026-21898

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution that uses the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. Prior to version 1.4.3, the Crypto AOS ProcessSecurity function does not perform valid bounds checking when parsing AOS frame hashes, leading to a potential issue.
Recommendations Versions prior to 1.4.3 should be updated to version 1.4.3 or later.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-21898
GHSA-7CH6-2PMG-M853

Affected Products

Cryptolib