OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
ID: 6ca56f15-e44f-5672-9ec5-060d7c280460
STIX ID: report--6ca56f15-e44f-5672-9ec5-060d7c280460
Feed Name: GBHackers
Threat Score
A newly disclosed OpenSSL DoS vulnerability dubbed “HollowByte” lets a remote unauthenticated attacker trigger unvalidated buffer pre-allocation from an 11-byte payload, causing heavy heap fragmentation, persistent RSS growth, and service disruption across many OpenSSL-using products; OpenSSL fixed the issue by switching to incremental buffer growth in v4.0.1 with backports, and organizations should prioritize upgrading internet-facing systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
