CVE-2026-79900: Heap overflow in KSL checksum initialization
boksksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 8.1.0.24 - Upgrade
Upgrade
boks-serverto a version that resolves this vulnerability.Fixed in 9.0.0.7 - Operational
Ensure the updated boks_ksllogsd process is running.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated KSL client can exploit it. The attack requires network access and valid authentication; no user interaction is required.
What input triggers the overflow?
The client must send a KSL start message whose MD field contains an OpenSSL-recognized checksum algorithm name that exceeds the fixed 16-byte checksum context field.
What is the likely impact of successful exploitation?
Successful exploitation can write beyond a heap allocation and cause a denial of service. The provided vector indicates no stated confidentiality or integrity impact.