bleeping-computer · Crawled Jul 17, 2026
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
Read original article ↗AI Summary
A vulnerability named HollowByte allows unauthenticated attackers to cause a denial-of-service condition on OpenSSL servers by sending an 11-byte malicious payload during the TLS handshake. The flaw stems from improper memory allocation based on unvalidated message length headers, leading to memory bloat and heap fragmentation. Although the issue has been silently patched in OpenSSL versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, affected systems remain at risk until updated, particularly given the widespread use of OpenSSL in web servers, runtimes, and databases.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.