OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.

OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta’s Red Team, which reported the denial-of-service bug and named it, published the

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

What’s the story behind the names of Cloudflare’s name servers? (2013)

What’s the story behind the names of Cloudflare’s name servers? (2013) Source: Hacker News

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm

Intelligence Is Not the Main Bottleneck

Intelligence Is Not the Main Bottleneck Source: Hacker News