CVE-2025-30216 is a heap-based buffer overflow in CryptoLib, a software-only implementation of CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) used to secure communications between spacecraft running cFS and ground stations. The issue affects CryptoLib version 1.3.3 and earlier. The vulnerability is in the Crypto_TM_ProcessSecurity function in crypto_tm.c at approximately line 1735. While processing the Secondary Header Length field of a TM protocol packet, the code fails to ensure that the declared Secondary Header Length is consistent with the packet's total length before performing a memcpy into the dynamically allocated buffer p_new_dec_frame. If the Secondary Header Length exceeds the actual packet length, the copy operation writes past the end of the heap allocation, corrupting adjacent heap memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Crypto_TM_ProcessSecurity, and rejecting packets whose Secondary Header Length is larger than the remaining or total packet length. Additional hardening measures such as enabling heap corruption detection, compiler/runtime memory protections, and isolating the vulnerable component can reduce exploit reliability but do not eliminate the underlying flaw.Patch, then assume compromise.
810fd66d592c883125272fef123c3240db2f170f. Apply the vendor-maintained fix and rebuild/redeploy CryptoLib in all affected environments. Validate that packet length checks are enforced before copying Secondary Header data and that malformed TM packets with inconsistent length fields are rejected safely.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-30216, a heap overflow vulnerability in NASA's CryptoLib (versions 1.3.3 and prior) within the Crypto_TM_ProcessSecurity function. The exploit consists of a single Python script (poc.py) and a README.md with detailed usage and technical background. The script operates in two modes: 'generate' creates a malicious TM protocol packet with a secondary header length field set to overflow the heap when processed by the vulnerable function; 'check' analyzes a given packet to determine if it would trigger the vulnerability. The exploit targets network-facing services or systems that process CCSDS TM protocol packets using the vulnerable CryptoLib implementation. No hardcoded IPs, URLs, or network endpoints are present, as the exploit is packet-based. The repository is structured for security research and demonstration purposes, with clear instructions and no external dependencies.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.