OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
ID: 5a8ce6ce-7191-5aba-b4de-dc3b32928fc2
STIX ID: report--5a8ce6ce-7191-5aba-b4de-dc3b32928fc2
Feed Name: cybersecurityNews.com
A newly disclosed OpenSSL denial-of-service vulnerability, dubbed "HollowByte," enables remote unauthenticated attackers to force excessive pre-allocated memory during the TLS handshake via a crafted 11-byte payload, leading to memory fragmentation and server OOM conditions; Okta Red Team testing demonstrated significant RAM exhaustion on NGINX, and OpenSSL mitigated the issue by switching to incremental buffer growth (merged into v4.0.1 and backported to 3.6.3, 3.5.7, 3.4.6, 3.0.21) but treated the change as a hardening improvement without a CVE, increasing the risk that some deployments may remain unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
