CNNVD-202601-1780 Information
CNNVD ID
CNNVD-202601-1780
Related CVE
- CNNVD Published: 2026-01-10
Description (Chinese)
CryptoLib是NASA开源的一个应用程序。用于使用 CCSDS 空间数据链路安全协议提供纯软件解决方案。 CryptoLib 1.4.3之前版本存在安全漏洞,该漏洞源于cryptography_encrypt函数分配的内存缓冲区未释放,可能导致内存耗尽。
Description (English)
Criptolib is an application from NASA open source. Provides pure software solutions using CCDS spatial data link security protocols. The previous version of CriptoLib 1.4.3 had a security loophole, which stemmed from the non-release of the memory buffer zone assigned by the cryptogram encrypt function, which could lead to depletion of the memory.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
美国国家航空航天局
Published
2026-01-10
Last Modified
2026-02-24
References
https://github.com/nasa/CryptoLib/commit/2372efd3da1ccb226b4297222e25f41ecc84821d https://github.com/nasa/CryptoLib/releases/tag/v1.4.3 https://github.com/nasa/CryptoLib/security/advisories/GHSA-r3wg-g8xv-gxvf
Patch
https://github.com/nasa/CryptoLib/releases
Share on: