Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-79900— Heap overflow in KSL checksum initialization

Quick assessment

Affected
Fortra BoKS Manager boks-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

boks_ksllogsd 在认证 KSL 启动消息的 MD 字段中接受一个校验和算法名称。受影响的版本会验证 OpenSSL 是否识别该摘要名称,但在复制之前并未检查该值是否能容纳在固定大小的 16 字节校验和上下文字段中。一个经过认证的 KSL 客户端可以提供一个超出大小限制但被 OpenSSL 识别的摘要名称,从而在堆分配区域末尾之外写入数据。

CVSS 6.5 · Medium EPSS 0.24% · P13

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProduct Version RangeStatus
Fortra BoKS Manager boks-server < 8.1.0.24 affected
< 9.0.0.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79900

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Heap overflow in KSL checksum initialization
Source: CVE Program / CVE List V5
Vulnerability Description
boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Fortra BoKS Manager boks-server 0 ~ 8.1.0.24 -

II. Public POCs for CVE-2026-79900

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79900

请登录查看更多情报信息。

Same Patch Batch · Fortra · 2026-10-01 · 8 CVEs total

CVE-2026-79901 9.9 CRITICAL Predictable Active Directory service-account passwords in BoKS Manager
CVE-2026-12627 9.8 CRITICAL Fortra's Core Privileged Access Manager (BoKS) autoregistration stack buffer overflow vuln
CVE-2026-79898 9.1 CRITICAL Fortra BoKS Manager crlserver command injection vulnerability
CVE-2026-14316 8.1 HIGH Heap buffer overflow in boks_sshd revoked-key error handling
CVE-2026-79899 7.9 HIGH Fortra BoKS Manager bccgethostcert insecure temporary file vulnerability
CVE-2026-79896 7.5 HIGH Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
CVE-2026-9864 4.8 MEDIUM Fortra BoKS Server Agent adjoin machine-account password generation vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-79900

No comments yet


Leave a comment