Heap overflow in KSL checksum initialization
Summary
| CVE | CVE-2026-79900 |
|---|---|
| State | PUBLISHED |
| Assigner | Fortra |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-01 15:17:31 UTC |
| Updated | 2026-10-01 20:34:26 UTC |
| Description | boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from df4dee71-de3a-4139-9588-11b62fe6c0ff
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-787 | CWE-787 CWE-787 Out-of-bounds write
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | df4dee71-de3a-4139-9588-11b62fe6c0ff | Secondary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | CNA | CVSS | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Fortra | BoKS Manager Boks-server | affected 8.1.0.24 semver | Not specified |
| CNA | Fortra | BoKS Manager Boks-server | affected 9.0.0.7 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.fortra.com/security/advisories/product-security/fi-2026-013 | df4dee71-de3a-4139-9588-11b62fe6c0ff | www.fortra.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line, and ensure the updated boks_ksllogsd is running.
There are currently no legacy QID mappings associated with this CVE.