---
id: CVE-2026-79900
title: >-
  boks_ksllogsd accepts a checksum algorithm name in the MD field of an
  authenticated KSL start message
summary: >-
  boks_ksllogsd accepts a checksum algorithm name in the MD field of an
  authenticated KSL start message. Affected releases verify that OpenSSL
  recognizes the digest name but do not verify that the value fits in a fixed
  16-byte checksum con…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
vendor: Fortra
product: BoKS Manager boks-server
affected:
  - boks_manager_boks-server < 8.1.0.24
  - boks_manager_boks-server < 9.0.0.7
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:31.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79900'
references:
  - url: 'https://www.fortra.com/security/advisories/product-security/fi-2026-013'
    label: df4dee71-de3a-4139-9588-11b62fe6c0ff
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-01T14:41:25.553335Z'
ingestedAt: '2026-10-01T14:46:26.720Z'
---

## Overview

boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
