Memory Bounds Checking Flaw in CryptoLib for Spacecraft Communication
CVE-2026-21898
8.2HIGH
What is CVE-2026-21898?
The CryptoLib library, utilized for securing communications between spacecraft and ground stations via the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP), contains a vulnerability in the Crypto_AOS_ProcessSecurity function. This flaw allows for memory reads without valid bounds checking when parsing AOS frame hashes, potentially compromising the integrity of the system. This issue has been addressed in version 1.4.3 of CryptoLib. Users are advised to upgrade to this version to ensure secure communications.
Affected Version(s)
CryptoLib < 1.4.3
