{"id":"CVE-2025-29912","summary":"CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity","details":"CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer underflow in the `Crypto_TC_ProcessSecurity` function of CryptoLib leads to a heap buffer overflow. The vulnerability is triggered when the `fl` (frame length) field in a Telecommand (TC) packet is set to 0. This underflow causes the frame length to be interpreted as 65535, resulting in out-of-bounds memory access. This critical vulnerability can be exploited to cause a denial of service (DoS) or potentially achieve remote code execution. Users of CryptoLib are advised to apply the recommended patch or avoid processing untrusted TC packets until a fix is available.","aliases":["GHSA-3f5x-r59x-p8cf"],"modified":"2026-08-12T15:16:22.787216Z","published":"2025-03-17T22:48:40.833Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122","CWE-191"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29912.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29912.json"},{"type":"ADVISORY","url":"https://github.com/nasa/CryptoLib/security/advisories/GHSA-3f5x-r59x-p8cf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29912"},{"type":"FIX","url":"https://github.com/nasa/CryptoLib/commit/ca39cb96f21e76102aefb956d2c8c0ba0bd143ca"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nasa/cryptolib","events":[{"introduced":"0"},{"fixed":"0d58c9a8cb9f7e96d67858d7ac125daaec0ca299"},{"fixed":"ca39cb96f21e76102aefb956d2c8c0ba0bd143ca"}],"database_specific":{"cpe":"cpe:2.3:a:nasa:cryptolib:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.4.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.3"],"database_specific":{"vanir_signatures":[{"target":{"file":"src/core/crypto_tc.c"},"deprecated":false,"digest":{"line_hashes":["146312352671957347138116315458094245629","224719578899484406993888791959364334734","336764517578373421295672448504052375199"],"threshold":0.9},"id":"CVE-2025-29912-6829b982","signature_type":"Line","signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/ca39cb96f21e76102aefb956d2c8c0ba0bd143ca"},{"digest":{"function_hash":"13558753078185090385275055473526822524","length":5014},"id":"CVE-2025-29912-75ec0971","signature_type":"Function","signature_version":"v1","source":"https://github.com/nasa/cryptolib/commit/ca39cb96f21e76102aefb956d2c8c0ba0bd143ca","target":{"file":"src/core/crypto_tc.c","function":"Crypto_TC_ProcessSecurity_Cam"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29912.json","vanir_signatures_modified":"2026-08-12T15:16:22Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}