Out-of-bounds Read Vulnerability in Fortra BoKS Manager's TLS ClientHello Parser
CVE-2026-79896
7.5HIGH
What is CVE-2026-79896?
Fortra BoKS Manager has a vulnerability in its custom TLS ClientHello parser utilized by boks_portmux, allowing remote unauthenticated attackers to exploit an out-of-bounds read. By crafting a malformed ClientHello message, attackers can disrupt the boks_portmux service. While the service typically restarts automatically, consistent exploitation can lead to prolonged interruptions, impacting overall system availability and security.
Affected Version(s)
BoKS Manager 8.1.0.0 <= 8.1.0.23
BoKS Manager 9.0.0.0 <= 9.0.0.6