CVE-2026-79896: Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read vulnerability
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boksportmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boksportmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 8.1.0.24 - Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 9.0.0.7
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker can exploit it by sending a malformed TLS ClientHello to boks_portmux. No credentials or user interaction are required.
What is the practical impact if boks_portmux is normally restarted automatically?
Automatic restart may restore the daemon after a single crash, but an attacker can repeatedly send malformed requests to keep the service interrupted. The stated impact is sustained denial of service.
Which versions should be deployed to remediate the issue?
Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7.