Database/Control plane, storage & DevOps
Fortra BoKS Manager: oversized digest name in a KSL start message overflows a fixed 16-byte checksum field
Impact
boks_ksllogsd takes the checksum algorithm name from the MD field of an authenticated KSL start message, checks only that OpenSSL recognizes the digest, and copies it into a fixed 16-byte context field without a length check. An authenticated KSL client can therefore write past the end of a heap allocation on the BoKS server. BoKS Manager is the central privileged-access and login-authorization service for a Unix server fleet, so the affected daemon sits on the path that decides whether administrators can log in to managed hosts at all; the record scores the outcome as availability loss only, with no confidentiality or integrity impact claimed. Losing that daemon degrades centralized access control for every host it serves, which on a GPU fleet means losing the ability to get onto nodes during an incident rather than losing tenant data.
Who can reach it
A KSL client that has already authenticated to the BoKS server, over the network. No unauthenticated path is described.
What to do
Apply the fixed BoKS Manager release named in Fortra advisory FI-2026-013 and restart the affected server daemon; the advisory is the authority on exact fixed versions, which the NVD record does not state. The action is confined to the BoKS server tier - no managed-host reboot or GPU node drain is implied. Until then, limit which hosts may open KSL sessions to the BoKS server.
References
Related entries
- Schneider Electric Data Center Expert - SOAP service endpoints: XML external entity processing on DCE SOAP endpointsCVE-2026-8045 · Schneider Electric Data Center Expert - SOAP service endpointsMedium
- Dell OpenManage Server Administrator (authorization checks): A second, distinct flaw in the same OMSA versionsCVE-2026-81439 · Dell OpenManage Server Administrator (authorization checks)Medium
- Airflow Akeyless provider: path-shaped Variable key bypasses the team-scope guard on secret lookupCVE-2026-86465 · Apache Airflow Akeyless provider (secrets backend, team-scope guard)Medium
- Jenkins Bitbucket Push and Pull Request Plugin: webhook payload can redirect credentialed requestsCVE-2026-92139 · Jenkins Bitbucket Push and Pull Request Plugin (webhook-supplied URLs)Medium
- Airflow HashiCorp provider: path-shaped Variable key crosses team scope in the Vault secrets backendCVE-2026-97636 · Apache Airflow HashiCorp provider (Vault secrets backend, team-scoped variable lookup)Medium
- Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients): Ceph's Python code constructs imaplib.IMAP4_SSL andNCVD-2024-010-ceph-python-bindings-imap4-ssl-s · Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.