Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYFORTINETVERIFIED

PUBLISHER UPDATE · FORTINET-PRODUCTS-89FF6F00E05934BB

FORTINET-PRODUCTS-89FF6F00E05934BB release notes and known issues

Heap overflow in kernel driver due to missing size validation

Scope: Fortinet products. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Revised on 2026-08-12 00:00:00

Improvements and security content

  • CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets. Revised on 2026-08-12 00:00:00

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Fortinet products

Affected versions

  • 7.3

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Official publisher evidence

FORTINETVERIFIED

Heap overflow in kernel driver due to missing size validation

Checked 7 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source