Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems.
Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7.