PT-2025-32586 · Cryptolib · Cryptolib

·

CVE-2025-54878

·

Published

2025-08-11

·

Updated

2025-09-10

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: CryptoLib versions 1.4.0 and earlier
Description: CryptoLib is a software solution utilizing the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow exists in the Initialization Vector (IV) setup logic for telecommand frames due to missing bounds checks when copying the IV into a newly allocated buffer. An attacker can supply a crafted TC frame, potentially corrupting heap memory and leading to undefined behavior, which may manifest as a denial of service or more severe exploitation.
Recommendations: CryptoLib versions prior to 1.4.0 are affected. Update to CryptoLib version 1.4.0 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54878
GHSA-9QPH-PXFM-Q9G4

Affected Products

Cryptolib