bleeping-computer · Crawled Jul 17, 2026

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

Read original article ↗

AI Summary

A vulnerability named HollowByte allows unauthenticated attackers to cause a denial-of-service condition on OpenSSL servers by sending an 11-byte malicious payload during the TLS handshake. The flaw stems from improper memory allocation based on unvalidated message length headers, leading to memory bloat and heap fragmentation. Although the issue has been silently patched in OpenSSL versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, affected systems remain at risk until updated, particularly given the widespread use of OpenSSL in web servers, runtimes, and databases.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.