#hollowbyte — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #hollowbyte, aggregated by home.social.
-
The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.
We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.
The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.
The severity framing, though… the numbers don't really back it. Full detail here: https://openssl-library.org/post/2026-07-21-hollowbyte/
-
The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.
We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.
The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.
The severity framing, though… the numbers don't really back it. Full detail here: https://openssl-library.org/post/2026-07-21-hollowbyte/
-
The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.
We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.
The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.
The severity framing, though… the numbers don't really back it. Full detail here: https://openssl-library.org/post/2026-07-21-hollowbyte/
-
The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.
We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.
The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.
The severity framing, though… the numbers don't really back it. Full detail here: https://openssl-library.org/post/2026-07-21-hollowbyte/
-
The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.
We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.
The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.
The severity framing, though… the numbers don't really back it. Full detail here: https://openssl-library.org/post/2026-07-21-hollowbyte/
-
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability https://www.securityweek.com/openssl-silently-fixes-hollowbyte-dos-vulnerability/
-
📢 OpenSSL HollowByte : un DoS en 11 octets permettant une fragmentation mémoire permanente
📝 ## 🔍 ContextePublié le 16 juillet 2026 par l'équipe Red Team d'Okta sur sec.okta.com, cet article présente la déco...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-20-openssl-hollowbyte-un-dos-en-11-octets-permettant-une-fragmentation-memoire-permanente/
🌐 source : https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
#DoS #HollowByte #Cyberveille -
The OpenSSL HollowByte vulnerability causes a severe memory leak that can easily crash servers. Learn how this 11-byte attack works and how to fix it.
#OpenSSL #HollowByte #CyberSecurity #MemoryLeak #Vulnerability
-
The OpenSSL HollowByte vulnerability causes a severe memory leak that can easily crash servers. Learn how this 11-byte attack works and how to fix it.
#OpenSSL #HollowByte #CyberSecurity #MemoryLeak #Vulnerability
-
A new OpenSSL HollowByte vulnerability enables remote DoS attacks using just 11 bytes. Learn how to protect your servers against this OpenSSL DoS attack.
-
A new OpenSSL HollowByte vulnerability enables remote DoS attacks using just 11 bytes. Learn how to protect your servers against this OpenSSL DoS attack.
-
#HollowByte #DDoS flaw bloats #OpenSSL server memory with 11-byte payload
-
#HollowByte #DDoS flaw bloats #OpenSSL server memory with 11-byte payload
-
#HollowByte #DDoS flaw bloats #OpenSSL server memory with 11-byte payload
-
#HollowByte #DDoS flaw bloats #OpenSSL server memory with 11-byte payload
-
#HollowByte #DDoS flaw bloats #OpenSSL server memory with 11-byte payload
-
📢 HollowByte : faille DoS dans OpenSSL exploitable avec 11 octets, correctif disponible
📝 📰 **Source** : BleepingComputer, publié le 17 juillet 2026, par Bill Toulas.
📖 cyberveille : https://cyberveille.ch/posts/2026-07-18-hollowbyte-faille-dos-dans-openssl-exploitable-avec-11-octets-correctif-disponible/
🌐 source : https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/
#DoS #HollowByte #Cyberveille