PT-2026-2135 · Cryptolib+1 · Cryptolib+1
Enitmar
+1
·
Published
2026-01-10
·
Updated
2026-01-10
·
CVE-2026-22027
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CryptoLib versions prior to 1.4.3
Description
CryptoLib is a software solution that uses the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft and a ground station. The
convert hexstring to byte array() function within the MariaDB SA interface lacks a capacity check when writing decoded bytes into a caller-provided buffer. This can lead to a heap buffer overflow when importing SA fields (e.g., IV, ARSN, ABM) from the database if a malformed or oversized hex string is present. The vulnerable function is convert hexstring to byte array().Recommendations
Update to CryptoLib version 1.4.3 or later.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cryptolib
Mariadb