Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.
OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta’s Red Team, which reported the denial-of-service bug and named it, published the According to The Hacker News, eleven bytes will make an unpatched openssl server set aside up to 131 kb of memory for a message that never arrives. on the glibc systems okta tested, that memory is gone until the process restarts.
openssl shipped the hollowbyte fix in june with no cve, no advisory, and no changelog entry pointing at it. okta’s red team, which reported the denial-of-service bug and named it, published the. The development comes amid ongoing regulatory scrutiny in the sector. The Hacker News reports that this marks a significant milestone for the industry. The The Hacker News report provides additional context on the implications for market participants and regulatory frameworks moving forward.
