logo

OpenSSL Fixes HollowByte Memory Exhaustion Bug

ID: 6a9459c5-611c-5e5b-9b30-880a456a3df7

STIX ID: report--6a9459c5-611c-5e5b-9b30-880a456a3df7

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Pierluigi Paganini

...
...

OpenSSL "HollowByte" is an 11-byte remote, unauthenticated memory-exhaustion DoS that causes OpenSSL to pre-allocate attacker-declared buffers and fragment the heap, allowing attackers to drive server resident memory up and force restarts; the issue was fixed by switching to incremental buffer growth and the fix is included in OpenSSL v4.0.1 and several backported releases—update OpenSSL packages promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.