*** This bug is a security vulnerability ***

Public security bug reported:

https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-
in-11-bytes/

"By sending a malicious payload of just 11 bytes, a remote,
unauthenticated attacker can force a server to allocate disproportionate
chunks of memory before any security handshake even begins."

"The OpenSSL team resolved this by moving to incremental buffer growth
(merged in PRs #30792, #30793, and #30794). This fix was silently
included as part of the OpenSSL v4.0.1 release, with silent backports to
release versions 3.6.3, 3.5.7, 3.4.6, and 3.0.21."

https://github.com/openssl/openssl/pull/30792
https://github.com/openssl/openssl/pull/30793
https://github.com/openssl/openssl/pull/30794

** Affects: openssl (Ubuntu)
     Importance: Undecided
         Status: New

** Information type changed from Private Security to Public Security

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161371

Title:
  OpenSSL HollowByte DoS

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2161371/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to