PT-2026-2135 · Cryptolib+1 · Cryptolib+1

Enitmar

+1

·

Published

2026-01-10

·

Updated

2026-01-10

·

CVE-2026-22027

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions CryptoLib versions prior to 1.4.3
Description CryptoLib is a software solution that uses the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. The convert hexstring to byte array() function within the MariaDB SA interface lacks a capacity check when writing decoded bytes into a caller-provided buffer. This can lead to a heap buffer overflow when importing SA fields (e.g., IV, ARSN, ABM) from the database if a malformed or oversized hex string is present. The vulnerable function is convert hexstring to byte array().
Recommendations Update to CryptoLib version 1.4.3 or later.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-22027
GHSA-3M35-M689-H29X

Affected Products

Cryptolib
Mariadb