*** This bug is a security vulnerability *** Public security bug reported:
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding- in-11-bytes/ "By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins." "The OpenSSL team resolved this by moving to incremental buffer growth (merged in PRs #30792, #30793, and #30794). This fix was silently included as part of the OpenSSL v4.0.1 release, with silent backports to release versions 3.6.3, 3.5.7, 3.4.6, and 3.0.21." https://github.com/openssl/openssl/pull/30792 https://github.com/openssl/openssl/pull/30793 https://github.com/openssl/openssl/pull/30794 ** Affects: openssl (Ubuntu) Importance: Undecided Status: New ** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2161371 Title: OpenSSL HollowByte DoS To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/2161371/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
