FI-2026-019 - Heap buffer overflow in boks_sshd revoked-key error handling
Severity
High
Published Date
01-Oct-2026
Updated Date
01-Oct-2026
Vulnerabilities
CVE-2026-14316
Notes
Description
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.