← All stories
● Covered by 3 sources · 3 reportsMedium impact

OpenSSL HollowByte Flaw Exposes Servers to Memory Exhaustion with Minimal Payload

🔄 Updated 74d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • HollowByte vulnerability affects OpenSSL TLS handshake process.
  • An 11-byte payload causes memory pre-allocation, creating a DoS risk.
  • Fixed versions: OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21.
  • No CVE or advisory issued for the fix.
  • Immediate update recommended to protect servers.

Overview of the Vulnerability

A security flaw identified as HollowByte has been discovered in OpenSSL. The flaw allows an 11-byte payload to trigger a server memory exhaustion process, leading to a denial-of-service (DoS) condition. This vulnerability affects the TLS handshake mechanism due to improper memory allocation for incoming message sizes.

Impact of the HollowByte Flaw

The HollowByte flaw forces vulnerable OpenSSL versions to allocate up to 131 KB of memory for a ClientHello message without verifying if the message will be completed. This can result in server freeze if exploited repeatedly. No authentication is required, making it easier for attackers to disrupt services.

Patch Details and Recommendations

OpenSSL has released patches for affected versions, including 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, on June 9. However, these patches were released without a CVE identifier or official advisories, which could leave users uninformed. Organizations using OpenSSL should prioritize upgrading to these fixed versions to mitigate the security risk.

Why Prompt Action is Urgent

OpenSSL is widely integrated into critical software systems. The potential for a denial-of-service attack without requiring authentication makes this vulnerability a significant risk. Prompt updates are necessary to protect internet communications and maintain operational effectiveness.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

OpenSSL patched a critical denial-of-service (DoS) vulnerability, termed HollowByte, which allowed attackers to exhaust server memory. The exploit could be executed with a minimal 11-byte payload, impacting various software that rely on OpenSSL, prompting the necessity for immediate updates to safeguard systems.

A flaw in OpenSSL allows unpatched servers to allocate large amounts of memory for incomplete TLS messages, leading to potential server freezes. Fixed versions released on June 9 include OpenSSL 4.0.1 and others, but there was no CVE or advisory issued, heightening risks for users.

The HollowByte vulnerability enables unauthenticated attackers to cause denial-of-service on OpenSSL servers by sending an 11-byte payload. OpenSSL has addressed the issue without issuing an identifier, necessitating organizations to upgrade to fixed versions immediately due to its widespread integration in critical software.