OpenSSL DoS Flaw Lets Unauthenticated Attackers Trigger Massive Memory Allocation
ID: bd5ac60c-aed4-5fe2-b52e-275fd1887ed0
STIX ID: report--bd5ac60c-aed4-5fe2-b52e-275fd1887ed0
Feed Name: Cyber Press
Threat Score
A newly disclosed OpenSSL flaw called "HollowByte" allows an 11-byte malicious TLS ClientHello to trigger unvalidated buffer pre-allocation, causing heavy heap fragmentation and persistent process RSS growth that can lock servers or cause OOM conditions; OpenSSL fixed the issue by switching to incremental buffer growth in v4.0.1 with backports to several 3.x releases, and administrators should urgently update internet-facing TLS endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
