CVE-2026-79900
Received Received - Intake

Heap Overflow in BOKS KSL Log Service

Vulnerability report for CVE-2026-79900, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Fortra

Description

boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can supply an oversized, OpenSSL-recognized digest name and write beyond the end of the heap allocation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in boks_ksllogsd where it accepts a checksum algorithm name in the MD field of an authenticated KSL start message. The issue is that while OpenSSL recognizes the digest name, the system does not verify if the value fits within a fixed 16-byte checksum context field before copying it. This allows an authenticated KSL client to provide an oversized digest name, leading to a heap-based buffer overflow.

Detection Guidance

This vulnerability involves a heap overflow in boks_ksllogsd due to improper validation of digest names in KSL start messages. Detection requires monitoring for unexpected heap corruption or crashes in the boks_ksllogsd process. Check logs for segmentation faults or memory corruption errors. Inspect network traffic for malformed KSL start messages with oversized MD fields.

Impact Analysis

An attacker with authenticated access to the KSL service could exploit this to write beyond allocated heap memory, potentially causing crashes, data corruption, or arbitrary code execution. This could lead to service disruption or unauthorized access to sensitive data depending on the system's configuration.

Compliance Impact

This vulnerability could impact compliance by enabling unauthorized access or data breaches, which are critical violations under GDPR and HIPAA. Organizations may face penalties or legal consequences if such incidents occur due to unpatched systems.

Mitigation Strategies

Apply vendor patches or updates addressing the checksum validation issue in boks_ksllogsd. Restrict network access to KSL services to trusted clients only. Monitor logs for unusual activity related to KSL start messages with oversized checksum algorithm names.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79900. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart