The record
Written from the 1 report below. Nothing here is unsourced.
- Okta's Red Team has disclosed a denial-of-service flaw called HollowByte in unpatched OpenSSL, where an 11-byte handshake message makes a server set aside up to 131 KB of memory for a body that never arrives.
- On glibc systems, the freed memory fragments and never returns to the kernel, so in Okta's testing a 1 GB NGINX server was killed and 25% of a 16 GB server's memory stayed locked.
- OpenSSL shipped a fix on June 9 in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, but treated it as a 'bug or hardening' change with no CVE, advisory, or changelog entry.
- That means normal patch pipelines and scanners have no identifier to match, making it hard for administrators — especially on backporting distributions like Red Hat — to know they need the fix.
What to watch next
- Whether OpenSSL responds on why HollowByte was triaged below Low and whether the fix reached the 1.1.1 and 1.0.2 extended-support branches
- Whether memory fragmentation from the flaw affects allocators other than glibc, per Okta's pending answer
- Whether OpenSSL commits to fixing the unfixed DTLS path, which still sizes buffers from peer-declared lengths
Coverage1
1 report
English national1
All filed from India
Named United States · glibc · NGINX · OpenBSD · OpenSSL · Alexandr Nedvedicky · Matt Caswell · Okta · Red Hat
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
