PT-2026-2134 · Cryptolib+1 · Cryptolib+1
Enitmar
+1
·
Published
2026-01-10
·
Updated
2026-01-10
·
CVE-2026-22026
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CryptoLib versions prior to 1.4.3
Description
CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) for secure communication between a spacecraft and a ground station. The
write callback function within the KMC crypto service client, prior to version 1.4.3, does not adequately limit the size of reallocated response buffers. This allows a malicious KMC server to send arbitrarily large HTTP responses, leading to excessive memory allocation and potential process termination. The vulnerable component is the libcurl function used for handling HTTP responses. The write callback function is specifically affected.Recommendations
Versions prior to 1.4.3 should be updated to version 1.4.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cryptolib
Libcurl