Out-of-Bounds Write in CryptoLib Affects NASA's Core Flight System
CVE-2026-21897
7.3HIGH
What is CVE-2026-21897?
CryptoLib is a software solution that secures communications between spacecraft and ground stations using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP). Prior to version 1.4.3, the implementation of the Crypto_Config_Add_Gvcid_Managed_Parameters function did not properly validate the gvcid_counter against the GVCID_MAN_PARAM_SIZE. This oversight allows for an out-of-bounds write, potentially affecting the gvcid_counter when it exceeds the allowed parameters. An attacker could exploit this vulnerability, leading to arbitrary values affecting the parameter management logic within the communication security system. This issue was remediated in version 1.4.3.
Affected Version(s)
CryptoLib < 1.4.3
