Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OpenSSL Patch Resolves Critical ‘HollowByte’ Vulnerability

OpenSSL Patch Resolves Critical ‘HollowByte’ Vulnerability

Posted on July 20, 2026 By CWS

An OpenSSL vulnerability, identified by Okta’s red team, poses a significant threat as it can lead to server memory exhaustion before any security handshakes occur. This flaw, dubbed ‘HollowByte’, can be exploited by attackers using a mere 11-byte malicious payload. By declaring a larger message body, attackers can initiate buffer pre-allocations that are not immediately released, causing a denial-of-service (DoS) scenario.

Understanding the HollowByte Vulnerability

The core issue with HollowByte lies in older versions of OpenSSL that pre-allocate buffer sizes based on the message body length declared in the handshake’s 4-byte header. This allocation occurs prior to data arrival, allowing attackers to send an 11-byte payload that results in an unvalidated buffer allocation reaching up to 131 KB. According to Okta, this leads to worker threads indefinitely waiting for non-arriving data.

Impact on Systems and Memory Management

The GNU C Library (glibc) complicates matters by retaining small-to-medium memory allocations for potential reuse, not returning them to the operating system when connections drop. Although OpenSSL may free the buffer, repeated payloads can exhaust server memory. Waves of connections with varied claimed sizes can prevent allocator reuse, bloating the server even after disconnection. The only remedy to recover memory is process termination. Testing revealed that systems with 1 GB RAM became unresponsive after 547 MB of memory was fragmented.

Patch Implementation and Affected Systems

OpenSSL version 4.0.1, along with backports to earlier versions, includes patches to address the HollowByte flaw by increasing buffer size based on actual data received, rather than relying on the handshake header. This update affects a wide range of applications and systems, including Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, and PostgreSQL, necessitating an upgrade to the patched OpenSSL version for continued secure operations.

In conclusion, the HollowByte vulnerability underscores the importance of timely software updates and patches. Organizations using OpenSSL should promptly upgrade to the latest patched versions to prevent potential DoS attacks and maintain secure system operations.

Security Week News Tags:Cybersecurity, DoS attack, glibc, HollowByte, memory exhaustion, OpenSSL, patch update, server security, Software Security, Vulnerability

Post navigation

Previous Post: Russian Spy Tactics Exploit IP Cameras in NATO, Ukraine
Next Post: Critical Kimai Docker Vulnerability Demands Urgent Update

Related Posts

Cisco Addresses Sixth SD-WAN Zero-Day Exploit of 2026 Cisco Addresses Sixth SD-WAN Zero-Day Exploit of 2026 Security Week News
Inti De Ceukelaire: Crafting Ethical Hacks Inti De Ceukelaire: Crafting Ethical Hacks Security Week News
Over 370 Organizations Take Part in GridEx VIII Grid Security Exercise Over 370 Organizations Take Part in GridEx VIII Grid Security Exercise Security Week News
New SharePoint Security Gap Exploited After Disclosure New SharePoint Security Gap Exploited After Disclosure Security Week News
Prosper Data Breach Impacts 17.6 Million Accounts Prosper Data Breach Impacts 17.6 Million Accounts Security Week News
Microsoft Addresses Defender Vulnerability ‘RoguePlanet’ Microsoft Addresses Defender Vulnerability ‘RoguePlanet’ Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark