OpenSSL Fixes HollowByte Memory Exhaustion Bug
ID: 6a9459c5-611c-5e5b-9b30-880a456a3df7
STIX ID: report--6a9459c5-611c-5e5b-9b30-880a456a3df7
Feed Name: Security Affairs
Threat Score
OpenSSL "HollowByte" is an 11-byte remote, unauthenticated memory-exhaustion DoS that causes OpenSSL to pre-allocate attacker-declared buffers and fragment the heap, allowing attackers to drive server resident memory up and force restarts; the issue was fixed by switching to incremental buffer growth and the fix is included in OpenSSL v4.0.1 and several backported releases—update OpenSSL packages promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
