hacker-news · Crawled Jul 17, 2026
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Read original article ↗AI Summary
The HollowByte flaw in older versions of OpenSSL allows attackers to cause denial-of-service by sending malicious 11-byte TLS handshake requests, leading to memory exhaustion. The vulnerability stems from OpenSSL trusting unverified message length fields in TLS headers, causing the server to allocate up to 131 KB per connection without validation. Due to glibc memory management behavior, freed memory is not returned to the kernel, resulting in heap fragmentation and sustained high memory usage. Notably, OpenSSL did not classify this issue as a vulnerability, releasing a fix without a CVE or advisory.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.