Heap buffer overflow in boks_sshd revoked-key error handling

FI-2026-019 - Heap buffer overflow in boks_sshd revoked-key error handling

Severity
High
Published Date
01-Oct-2026
Updated Date
01-Oct-2026
Vulnerabilities
CVE-2026-14316
 
Notes
Description

The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation. 

 

Vulnerabilities

 
Heap buffer overflow in boks_sshd revoked-key error handling
Severity
High
CVE
CVE-2026-14316
CWE
CWE-122:Heap-based buffer overflow
Discovery Date
28-May-2026
CSSv3.1
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N)
Affected Products
Vulnerability Notes
References