top of page
perceptive_background_267k.jpg

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a…

Published:

9 January 2026 at 23:00:00

Alert date:

10 January 2026 at 13:10:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

CVE-2026-21897 affects NASA's CryptoLib, a software solution for securing spacecraft communications using CCSDS Space Data Link Security Protocol. The vulnerability exists in the Crypto_Config_Add_Gvcid_Managed_Parameters function prior to version 1.4.3, where improper boundary checking allows writing past the end of an array. This causes an out-of-bounds write that overwrites the gvcid_counter variable with arbitrary values, potentially affecting parameter lookup and registration logic. The issue impacts communications security between spacecraft running core Flight System (cFS) and ground stations. The vulnerability has been patched in version 1.4.3.

Technical details

Mitigation steps:

Affected products:

NASA CryptoLib
core Flight System

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page