Description
boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Memory corruption via heap overflow that can lead to arbitrary code execution or service disruption
Action: Apply Patch
AI Analysis

Impact

An authenticated KSL client can send a start message that contains a checksum algorithm name. The boks_ksllogsd service copies the name into a fixed 16‑byte buffer without verifying its length. If the supplied name is longer than 16 bytes but is still a digest recognized by OpenSSL, the copy operation overruns the heap allocation. The overflow corrupts adjacent memory and can cause the daemon to crash or, if the overwritten memory contains executable code, enable arbitrary execution. This classic buffer overflow is identified as CWE‑787.

Affected Systems

The vulnerability exists in the boks-ksllogsd component of Fortra BoKS Manager. All releases before boks-server 8.1.0.24 on the 8.x maintenance line or before boks-server 9.0.0.7 on the 9.x line are affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, but the memory corruption can be triggered only by an authenticated attacker. Therefore an adversary must first obtain valid credentials or compromise a trusted client. Once authenticated, the attacker can craft a KSL start message with an oversized checksum name to trigger the overflow, potentially leading to process termination or code execution. The impact is limited to the boks_ksllogsd process but could extend to the overall BoKS Manager installation if elevated privileges are achieved.

Generated by OpenCVE AI on October 1, 2026 at 16:27 UTC.

Remediation

Vendor Solution

Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7, as appropriate for the installed maintenance line, and ensure the updated boks_ksllogsd is running.


OpenCVE Recommended Actions

  • Upgrade the boks-server package to the latest release (8.1.0.24 on the 8.x line or 9.0.0.7 on the 9.x line) and restart the boks_ksllogsd service.
  • If an immediate upgrade is not possible, disable or remove external interfaces that allow KSL clients to connect, preventing authenticated clients from sending the malicious start message.
  • Implement monitoring on the boks_ksllogsd process to detect abnormal memory usage or crashes that may indicate an attempted exploitation.

Generated by OpenCVE AI on October 1, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.
Title Heap overflow in KSL checksum initialization
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-10-01T14:42:09.954Z

Reserved: 2026-08-25T14:50:14.032Z

Link: CVE-2026-79900

cve-icon Vulnrichment

Updated: 2026-10-01T14:42:00.752Z

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:31.920

Modified: 2026-10-01T15:17:31.920

Link: CVE-2026-79900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses