[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fanegedMRvDEpazC04zC1EIRt6ocZkWRdAs9txHTvwD8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"6e5f8aec-4c52-4bd9-bceb-c40bd50f420a","openssl-hollowbyte-flaw-enables-memory-exhaustion-via-tiny-tls-requests","9a6bad82-bbca-419d-9990-aeaa86aa32a7","OpenSSL HollowByte Flaw Enables Memory Exhaustion via Tiny TLS Requests","The HollowByte vulnerability exposes a critical resource management flaw in OpenSSL where malformed TLS handshake headers trick the server into pre-allocating up to 131 KB of memory per connection — memory that is never released on glibc-based systems until a process restart. An attacker needs only 11 bytes per request to trigger this, making denial-of-service attacks cheap and connection-rate limits ineffective as a defense. Compounding the risk, OpenSSL classified the fix as a 'hardening' change rather than a vulnerability, bypassing CVE assignment and formal advisories — meaning many organizations relying on vulnerability feeds alone would never know to patch. This highlights the danger of vendor classification decisions that obscure security impact and underscores why proactive patch tracking beyond CVE databases is essential.","**Immediate Actions:**\n- Upgrade all OpenSSL deployments to the June 2026 patched release immediately, regardless of CVE absence.\n- Audit TLS-terminating services (load balancers, web servers, API gateways) to confirm OpenSSL version and patch status.\n\n**Detection Measures:**\n- Deploy memory utilization monitoring and alerting on all internet-facing TLS endpoints to detect abnormal allocation growth.\n- Configure process-level memory limits and automatic restart policies to reduce impact window of memory exhaustion attacks.\n- Subscribe to upstream vendor release notes and commit logs (not just CVE feeds) to catch security fixes classified as 'hardening'.\n\n**Long-Term Improvements:**\n- Establish a software bill of materials (SBOM) practice to maintain full inventory of OpenSSL usage across all products and dependencies.\n- Implement a vendor-agnostic patch management policy that triggers review for any cryptographic library update, CVE-assigned or not.\n- Enforce network segmentation and rate-limiting at the perimeter to reduce exposure of TLS endpoints to unauthenticated bulk connection attempts.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7.1 – Establish and Maintain a Vulnerability Management Process","CIS Control 7.3 – Perform Automated Operating System Patch Management","CIS Control 12.2 – Establish and Maintain a Secure Network Architecture","NIST SP 800-40 Rev. 4 – Guide to Enterprise Patch Management","NIST SI-2 – Flaw Remediation","NIST SI-10 – Information Input Validation","NIST SC-5 – Denial of Service Protection","NIST CA-7 – Continuous Monitoring","ITIL – Change and Release Management (patch deployment workflows)","NIST SSDF PW.5 – Create Source Code by Adhering to Secure Coding Practices","published","2026-07-17T22:21:01.518278+00:00","2026-07-17T22:21:01.217+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fopenssl-hollowbyte-flaw-could-freeze.html","openssl-hollowbyte-flaw-could-freeze-server-memory-with-11-byte-tls-requests-d32c62","OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[43,49],{"id":44,"date":45,"edition":46,"title":47,"audio_url":48},"41f31daa-3c25-4318-b9be-29831f344e09","2026-07-19","afternoon","ThreatNoir Weekend Brief — July 19","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-19\u002Fthreatnoir-afternoon-brief-2026-07-19.mp3",{"id":50,"date":51,"edition":52,"title":53,"audio_url":54},"e6e1606e-6efa-4379-a809-f53e68d45699","2026-07-18","morning","ThreatNoir Weekend Brief — July 18","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-18\u002Fthreatnoir-morning-brief-2026-07-18.mp3"]