logo

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

ID: 719c2d6d-4914-5657-b865-b92e2ead46ff

STIX ID: report--719c2d6d-4914-5657-b865-b92e2ead46ff

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

OpenSSL contained a denial-of-service flaw dubbed "HollowByte" where an attacker-supplied TLS handshake length causes immediate allocation of up to ~131 KB per connection; when many such connections use varying lengths and attackers drop them, glibc's allocator fragments the heap and memory remains consumed until restart, allowing servers to be OOM-killed. Okta's Red Team reported the issue and OpenSSL released quiet fixes across multiple branches (June 9 releases) without assigning a CVE or prominent advisory; DTLS was not fixed and downstream packages may not surface the change, leaving many deployments at risk despite available patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.