OpenSSL 'HollowByte' DoS Flaw Exploitable with 11-Byte TLS Requests
A denial-of-service (DoS) vulnerability, dubbed ‘HollowByte,’ has been discovered in OpenSSL. This flaw allows unauthenticated attackers to consume significant server memory (up to 131 KB) with a mere 11-byte malicious TLS request. The affected memory on glibc systems remains allocated until the process restarts, making it a persistent DoS vector. OpenSSL quietly patched this issue without a CVE or public advisory, highlighting the need for vigilance.