GPU VulnDB

Database/Control plane, storage & DevOps

Fortra BoKS Manager: oversized digest name in a KSL start message overflows a fixed 16-byte checksum field

CVSS 6.5CVE-2026-79900Control plane, storage & DevOpscurated

Impact

boks_ksllogsd takes the checksum algorithm name from the MD field of an authenticated KSL start message, checks only that OpenSSL recognizes the digest, and copies it into a fixed 16-byte context field without a length check. An authenticated KSL client can therefore write past the end of a heap allocation on the BoKS server. BoKS Manager is the central privileged-access and login-authorization service for a Unix server fleet, so the affected daemon sits on the path that decides whether administrators can log in to managed hosts at all; the record scores the outcome as availability loss only, with no confidentiality or integrity impact claimed. Losing that daemon degrades centralized access control for every host it serves, which on a GPU fleet means losing the ability to get onto nodes during an incident rather than losing tenant data.

Who can reach it

A KSL client that has already authenticated to the BoKS server, over the network. No unauthenticated path is described.

What to do

Apply the fixed BoKS Manager release named in Fortra advisory FI-2026-013 and restart the affected server daemon; the advisory is the authority on exact fixed versions, which the NVD record does not state. The action is confined to the BoKS server tier - no managed-host reboot or GPU node drain is implied. Until then, limit which hosts may open KSL sessions to the BoKS server.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.