CVE-2026-79896 PUBLISHED

Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability

Assigner: Fortra
Reserved: 25.08.2026 Published: 01.10.2026 Updated: 01.10.2026

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Fortra
Product BoKS Manager
Versions Default: unknown
  • affected from 8.1.0.0 to 8.1.0.23 (incl.)
  • affected from 9.0.0.0 to 9.0.0.6 (incl.)

Workarounds

Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems.

Solutions

Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7.

References

Problem Types

  • CWE-125 Out-of-bounds read CWE

Impacts

  • CAPEC-125 Flooding