Heap Buffer Overflow in CryptoLib Affects NASA Software Solutions
CVE-2025-29913
8.9HIGH
What is CVE-2025-29913?
A heap buffer overflow vulnerability exists in the Crypto_TC_Prep_AAD
function of CryptoLib, impacting versions 1.3.3 and earlier. This flaw is caused by the incorrect calculation of the MAC start index during processing, which can lead to an unsigned integer underflow. As a result, an attacker can craft a malicious telecommand frame that accesses out-of-bounds memory, enhancing the risk of Denial of Service attacks or arbitrary code execution. The defect is documented and remains unresolved in the repository.
Affected Version(s)
CryptoLib <= 1.3.3