Summary
Key Points:
- OpenSSL has a vulnerability known as the HollowByte flaw, which allows attackers to exploit the TLS handshake process by sending an 11-byte message, causing excessive memory allocation and potential denial-of-service (DoS) conditions.
- The flaw affects multiple OpenSSL versions (4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21) and can lead to significant memory fragmentation, with tests showing up to 25% of system memory being locked without exceeding connection limits.
- It is recommended that organizations upgrade to the patched versions of OpenSSL immediately and restart any services using the old versions to mitigate this risk.
Technical Details: The HollowByte flaw does not have a CVE identifier and was classified as a "bug or hardening" fix by OpenSSL, despite its potential impact on server memory management.
MITRE ATT&CK Techniques: None mentioned
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.