Out-of-Bounds Write in CryptoLib Affects NASA's Core Flight System
CVE-2026-21897

7.3HIGH

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
10 January 2026

What is CVE-2026-21897?

CryptoLib is a software solution that secures communications between spacecraft and ground stations using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP). Prior to version 1.4.3, the implementation of the Crypto_Config_Add_Gvcid_Managed_Parameters function did not properly validate the gvcid_counter against the GVCID_MAN_PARAM_SIZE. This oversight allows for an out-of-bounds write, potentially affecting the gvcid_counter when it exceeds the allowed parameters. An attacker could exploit this vulnerability, leading to arbitrary values affecting the parameter management logic within the communication security system. This issue was remediated in version 1.4.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CryptoLib < 1.4.3

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.