news.mlab.sh
7 results
vulnerability

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

A memory-exhaustion denial-of-service vulnerability, dubbed HollowByte, exists in OpenSSL versions 3.6.3, 3.5.7, 3.4.6, 3.0.21, 4.0.1, 3.6.2, and 3.6.3. The vulnerability stems from a flawed memory allocation process during TLS handshakes, where OpenSSL allocates a buffer size based on the client's claimed message leng…

The Hacker News · Jul 17, 2026 High