OpenSSL HollowByte: A DoS Hiding in 11 Bytes
Summary
Okta Red Team reports HollowByte, a DoS vulnerability in OpenSSL. An 11-byte header can trigger unvalidated allocation and memory fragmentation, allowing unauthenticated remote attackers to exhaust memory; fix implemented in OpenSSL v4.0.1 with backports, and upgrading OpenSSL is advised.