A security flaw identified as HollowByte has been discovered in OpenSSL. The flaw allows an 11-byte payload to trigger a server memory exhaustion process, leading to a denial-of-service (DoS) condition. This vulnerability affects the TLS handshake mechanism due to improper memory allocation for incoming message sizes.
The HollowByte flaw forces vulnerable OpenSSL versions to allocate up to 131 KB of memory for a ClientHello message without verifying if the message will be completed. This can result in server freeze if exploited repeatedly. No authentication is required, making it easier for attackers to disrupt services.
OpenSSL has released patches for affected versions, including 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, on June 9. However, these patches were released without a CVE identifier or official advisories, which could leave users uninformed. Organizations using OpenSSL should prioritize upgrading to these fixed versions to mitigate the security risk.
OpenSSL is widely integrated into critical software systems. The potential for a denial-of-service attack without requiring authentication makes this vulnerability a significant risk. Prompt updates are necessary to protect internet communications and maintain operational effectiveness.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
OpenSSL patched a critical denial-of-service (DoS) vulnerability, termed HollowByte, which allowed attackers to exhaust server memory. The exploit could be executed with a minimal 11-byte payload, impacting various software that rely on OpenSSL, prompting the necessity for immediate updates to safeguard systems.
A flaw in OpenSSL allows unpatched servers to allocate large amounts of memory for incomplete TLS messages, leading to potential server freezes. Fixed versions released on June 9 include OpenSSL 4.0.1 and others, but there was no CVE or advisory issued, heightening risks for users.
The HollowByte vulnerability enables unauthenticated attackers to cause denial-of-service on OpenSSL servers by sending an 11-byte payload. OpenSSL has addressed the issue without issuing an identifier, necessitating organizations to upgrade to fixed versions immediately due to its widespread integration in critical software.