Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenSSL Patch Resolves Critical ‘HollowByte’ Vulnerability

OpenSSL Patch Resolves Critical ‘HollowByte’ Vulnerability

Posted on July 20, 2026 By CWS

An OpenSSL vulnerability, identified by Okta’s red team, poses a significant threat as it can lead to server memory exhaustion before any security handshakes occur. This flaw, dubbed ‘HollowByte’, can be exploited by attackers using a mere 11-byte malicious payload. By declaring a larger message body, attackers can initiate buffer pre-allocations that are not immediately released, causing a denial-of-service (DoS) scenario.

Understanding the HollowByte Vulnerability

The core issue with HollowByte lies in older versions of OpenSSL that pre-allocate buffer sizes based on the message body length declared in the handshake’s 4-byte header. This allocation occurs prior to data arrival, allowing attackers to send an 11-byte payload that results in an unvalidated buffer allocation reaching up to 131 KB. According to Okta, this leads to worker threads indefinitely waiting for non-arriving data.

Impact on Systems and Memory Management

The GNU C Library (glibc) complicates matters by retaining small-to-medium memory allocations for potential reuse, not returning them to the operating system when connections drop. Although OpenSSL may free the buffer, repeated payloads can exhaust server memory. Waves of connections with varied claimed sizes can prevent allocator reuse, bloating the server even after disconnection. The only remedy to recover memory is process termination. Testing revealed that systems with 1 GB RAM became unresponsive after 547 MB of memory was fragmented.

Patch Implementation and Affected Systems

OpenSSL version 4.0.1, along with backports to earlier versions, includes patches to address the HollowByte flaw by increasing buffer size based on actual data received, rather than relying on the handshake header. This update affects a wide range of applications and systems, including Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, and PostgreSQL, necessitating an upgrade to the patched OpenSSL version for continued secure operations.

In conclusion, the HollowByte vulnerability underscores the importance of timely software updates and patches. Organizations using OpenSSL should promptly upgrade to the latest patched versions to prevent potential DoS attacks and maintain secure system operations.

Security Week News Tags:Cybersecurity, DoS attack, glibc, HollowByte, memory exhaustion, OpenSSL, patch update, server security, Software Security, Vulnerability

Post navigation

Previous Post: Russian Spy Tactics Exploit IP Cameras in NATO, Ukraine
Next Post: Critical Kimai Docker Vulnerability Demands Urgent Update

Related Posts

Cogent Secures M to Enhance AI for Vulnerability Management Cogent Secures $42M to Enhance AI for Vulnerability Management Security Week News
PromptLock Only PoC, but AI-Powered Ransomware Is Real PromptLock Only PoC, but AI-Powered Ransomware Is Real Security Week News
Daylight Raises  Million for AI-Powered MDR Platform Daylight Raises $33 Million for AI-Powered MDR Platform Security Week News
Iran-Linked Group Claims Cal Water Cyber Breach Iran-Linked Group Claims Cal Water Cyber Breach Security Week News
RapperBot Botnet Disrupted, American Administrator Indicted RapperBot Botnet Disrupted, American Administrator Indicted Security Week News
The Challenges of OT Security in a Converging IT World The Challenges of OT Security in a Converging IT World Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark