DigiNews

Tech Watch by Johan Denoyer

← Back to articles

OpenSSL HollowByte: A DoS Hiding in 11 Bytes

Quality: 8/10 Relevance: 9/10

Summary

Okta Red Team reports HollowByte, a DoS vulnerability in OpenSSL. An 11-byte header can trigger unvalidated allocation and memory fragmentation, allowing unauthenticated remote attackers to exhaust memory; fix implemented in OpenSSL v4.0.1 with backports, and upgrading OpenSSL is advised.

🚀 Service construit par Johan Denoyer