SICHERHEIT & DATENSCHUTZ

OpenSSL HollowByte Security Vulnerability Discovered

OpenSSL HollowByte Security Vulnerability Discovered

A new security vulnerability in OpenSSL could bring servers to a halt with 11-byte TLS requests.

A recently discovered security vulnerability in OpenSSL, known as HollowByte, could have serious implications for unpatched servers. This vulnerability allows an unprotected OpenSSL server to reserve up to 131 KB of memory for a message that never arrives. This could lead to a Denial-of-Service (DoS) as the reserved memory remains lost until the process is restarted.

The HollowByte vulnerability was identified and reported by Okta's Red Team. The researchers found that the vulnerability occurs on glibc systems that were tested by Okta. The fact that a server can be put into a state where it blocks memory by sending a mere 11-byte TLS request is concerning.

Details on the HollowByte Vulnerability

OpenSSL released a fix for the HollowByte vulnerability in June 2026. Interestingly, this patch was released without an associated Common Vulnerabilities and Exposures (CVE) number, without an official announcement, and without an entry in the changelog. This has raised concerns regarding transparency and communication of security updates within the OpenSSL community.

The discovery of the HollowByte vulnerability raises questions about the security practices applied during the development and maintenance of OpenSSL. The fact that such a critical issue was addressed without proper documentation could lead many administrators and companies to be unaware of the need to update their systems.

Okta's Red Team has classified the vulnerability as serious and recommends that all affected systems be updated immediately. The impact of this vulnerability could be far-reaching, especially in environments where OpenSSL is widely used, such as in web servers and other network services.

Reactions from the Security Community

The security community has reacted with concern to the discovery of the HollowByte vulnerability. Experts warn that unprotected systems are vulnerable to attacks that could exploit this weakness. The fact that the patch was released without proper communication could lead many administrators to unknowingly operate vulnerable systems.

The discussion surrounding the HollowByte vulnerability has also highlighted the need for better documentation and communication of security updates within the OpenSSL community. Many in the industry are calling for a review of the processes that lead to the release of security updates to ensure that such critical information is not overlooked.

The HollowByte vulnerability is another example of the challenges faced by the security community in keeping software secure. The discovery of such vulnerabilities underscores the importance of companies and organizations taking proactive measures to protect their systems.

The OpenSSL developers have acknowledged the significance of the vulnerability and are working to improve communication regarding future security updates. The HollowByte vulnerability could serve as a wake-up call for the entire industry to rethink security practices and ensure that all systems are regularly updated.

comment Kommentare (0)

Noch keine Kommentare. Schreiben Sie den ersten!

Kommentar hinterlassen