OpenSSL HollowByte Flaw Puts Servers at Risk with 11-Byte Malicious Payload
OpenSSL's HollowByte flaw puts servers at risk with 11-byte malicious payload, causing denial-of-service conditions. Patching and DoS protection measures are essential.

An 11-byte malicious payload can freeze server memory due to the OpenSSL HollowByte flaw, a recently disclosed vulnerability that allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers.
Understanding the HollowByte Flaw
The HollowByte flaw is a denial-of-service vulnerability in OpenSSL that can be exploited by sending a malicious payload of just 11 bytes. This payload can cause the server to allocate up to 131 KB of memory, leading to a denial-of-service condition. The vulnerability was discovered by Okta's Red Team and has been patched by OpenSSL, although no CVE or advisory was issued.
Vulnerability Mechanics
The HollowByte flaw works by exploiting the way OpenSSL handles TLS requests. When an attacker sends an 11-byte malicious payload, the server sets aside a large amount of memory for a message that never arrives. On systems using glibc, this memory is not released until the process is restarted, leading to a denial-of-service condition.
Who Is Affected
Any organization using OpenSSL servers is potentially at risk from the HollowByte flaw. This includes a wide range of industries and sectors, from finance and healthcare to government and technology.
What the Sceptics Say
Some sceptics may argue that the HollowByte flaw is not a significant threat, as it only allows for a denial-of-service attack and does not provide an avenue for code execution or data theft. However, this perspective overlooks the potential impact of a successful DoS attack, which can still cause significant disruption and financial loss.
How to Defend
- Apply the latest OpenSSL patches to prevent exploitation of the HollowByte flaw.
- Implement robust denial-of-service protection measures, such as rate limiting and IP blocking.
- Monitor server memory usage and performance to quickly detect potential attacks.
Key Takeaways
- Security Teams: Prioritize patching OpenSSL servers and implementing DoS protection measures.
- CISOs: Ensure that your organization's risk management strategy includes denial-of-service attacks and that appropriate mitigation measures are in place.
- Developers: Be aware of the potential for denial-of-service vulnerabilities in your applications and take steps to prevent them.
- End Users: Be cautious when using online services and report any suspicious activity or service disruptions to the relevant authorities.
Related Security Coverage
Sources
- The Hacker News: OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
- BleepingComputer: HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
- Security Affairs: OpenSSL Fixes HollowByte Memory Exhaustion Bug
- GBHackers: OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
This article is published by AnalyticsGlobe for informational purposes only. It does not constitute financial, legal, investment, or professional advice of any kind. यह लेख केवल जानकारी के उद्देश्य से प्रकाशित किया गया है — कोई भी निर्णय लेने से पहले आधिकारिक स्रोतों से पुष्टि करें।
Cybersecurity Agent
Published under the research and editorial standards of AnalyticsGlobe. All research is independently produced and subject to our editorial guidelines.