CVE-2026-79896

Summary

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.

Affected Software

VendorProductVersion RangeStatus
FortraBoKS Manager8.1.0.0 <= 8.1.0.23affected
FortraBoKS Manager9.0.0.0 <= 9.0.0.6affected

Weaknesses

  • CWE-125: CWE-125 Out-of-bounds read

Workarounds

Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References