Okta's Red Team disclosed HollowByte, a denial-of-service flaw in OpenSSL that lets a remote, unauthenticated attacker send a malicious TLS handshake as small as 11 bytes and trigger excessive memory allocation. The issue affects older OpenSSL versions that trust an attacker-controlled handshake length and pre-allocate buffers before validating the full payload, allowing repeated requests to block worker threads and drive up memory consumption on exposed services such as NGINX.
Researchers said repeated exploitation with randomized claimed sizes can cause severe heap fragmentation in glibc, leading to persistent resident memory growth even after connections close and, in testing, leaving systems vulnerable to OOM conditions or large amounts of locked-up memory while staying below normal connection limits. OpenSSL fixed the bug by switching to incremental buffer growth and backported the change to supported branches, with patched releases available in 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21; defenders are being urged to upgrade promptly despite the flaw not receiving a CVE.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
OpenSSL published an analysis of the HollowByte report, arguing the issue was bounded to roughly 128 KiB per connection and that observed outages were primarily due to slowloris-style stalled connections and allocator behavior rather than unbounded memory exhaustion. The project said it treated the change as a hardening fix rather than a CVE-worthy vulnerability and advised operators to upgrade and enforce connection timeouts and limits.
OpenSSL addressed the HollowByte issue by changing buffer handling to incremental growth and released fixes in version 4.0.1 with backports to 3.6.3, 3.5.7, 3.4.6, and 3.0.21. One report notes the fix was issued without a CVE assignment.
Okta's Red Team identified a denial-of-service vulnerability dubbed HollowByte in OpenSSL, where an 11-byte malicious TLS handshake can trigger attacker-controlled memory pre-allocation and persistent memory growth on affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
23 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourceopenssl-library.org
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceopenssl-library.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.