Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7.
Workaround
Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems.
References
History
Thu, 01 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption. | |
| Title | Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-10-01T16:02:49.186Z
Reserved: 2026-08-25T14:50:07.493Z
Link: CVE-2026-79896
No data.
Status : Received
Published: 2026-10-01T16:17:59.940
Modified: 2026-10-01T17:17:32.043
Link: CVE-2026-79896
No data.
OpenCVE Enrichment
Updated: 2026-10-01T17:00:15Z
Weaknesses