logo

OpenSSL DoS Flaw Lets Unauthenticated Attackers Trigger Massive Memory Allocation

ID: bd5ac60c-aed4-5fe2-b52e-275fd1887ed0

STIX ID: report--bd5ac60c-aed4-5fe2-b52e-275fd1887ed0

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Tamilselvan

...
...

A newly disclosed OpenSSL flaw called "HollowByte" allows an 11-byte malicious TLS ClientHello to trigger unvalidated buffer pre-allocation, causing heavy heap fragmentation and persistent process RSS growth that can lock servers or cause OOM conditions; OpenSSL fixed the issue by switching to incremental buffer growth in v4.0.1 with backports to several 3.x releases, and administrators should urgently update internet-facing TLS endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.