home.social

#hollowbyte — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hollowbyte, aggregated by home.social.

fetched live
  1. The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.

    We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.

    The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.

    The severity framing, though… the numbers don't really back it. Full detail here: openssl-library.org/post/2026-

    #hollowbyte #openssl

  2. The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.

    We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.

    The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.

    The severity framing, though… the numbers don't really back it. Full detail here: openssl-library.org/post/2026-

    #hollowbyte #openssl

  3. The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.

    We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.

    The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.

    The severity framing, though… the numbers don't really back it. Full detail here: openssl-library.org/post/2026-

    #hollowbyte #openssl

  4. The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.

    We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.

    The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.

    The severity framing, though… the numbers don't really back it. Full detail here: openssl-library.org/post/2026-

    #hollowbyte #openssl

  5. The "HollowByte" report got a good deal of attention this past week. There were fair questions in it, so we looked into it properly and wrote up what we found.

    We reproduced their own scenario. The memory growth is bounded - it plateaus and gets reused rather than running away, even without our change. And the outage they describe is a stalled-connection problem, not the allocation itself.

    The one thing they had right: we should have shipped a release and a findable advisory, not a quiet backport.

    The severity framing, though… the numbers don't really back it. Full detail here: openssl-library.org/post/2026-

    #hollowbyte #openssl

  6. 📢 OpenSSL HollowByte : un DoS en 11 octets permettant une fragmentation mémoire permanente
    📝 ## 🔍 Contexte

    Publié le 16 juillet 2026 par l'équipe Red Team d'Okta sur sec.okta.com, cet article présente la déco...
    📖 cyberveille : cyberveille.ch/posts/2026-07-2
    🌐 source : sec.okta.com/articles/2026/06/
    #DoS #HollowByte #Cyberveille