---
id: CVE-2026-79896
title: >-
  Fortra BoKS Manager boks_portmux TLS ClientHello out-of-bounds read
  vulnerability
summary: >-
  Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom
  TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker
  can submit a malformed ClientHello and terminate boks_portmux. Although the
  dae…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-125
vendor: Fortra
product: BoKS Manager
affected:
  - boks_manager >= 8.1.0.0 <= 8.1.0.23
  - boks_manager >= 9.0.0.0 <= 9.0.0.6
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:09:21.099Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-79896'
references:
  - url: 'https://www.fortra.com/security/advisories/product-security/fi-2026-016'
tags:
  - cve.org
ingestedAt: '2026-10-01T15:48:17.894Z'
---

## Overview

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.

## Affected

- `boks_manager >= 8.1.0.0 <= 8.1.0.23`
- `boks_manager >= 9.0.0.0 <= 9.0.0.6`

## Remediation

Upgrade to boks-server 8.1.0.24 or boks-server 9.0.0.7.

### Workarounds

Until a fixed release is installed, restrict network access to boks_portmux listeners to trusted systems.
