Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability

FI-2026-016 - Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability

Severity
High
Published Date
01-Oct-2026
Updated Date
01-Oct-2026
Vulnerabilities
CVE-2026-79896
 
Notes
Description

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.

 

Vulnerabilities

 
Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
Severity
High
CVE
CVE-2026-79896
CWE
CWE-125:Out-of-bounds read
Discovery Date
25-Aug-2026
CSSv3.1
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Products
Vulnerability Notes
References