Back Feeds.4Sysops HollowByte flaw allows unauthenticated OpenSSL memory exhaustion
A newly discovered vulnerability named HollowByte allows unauthenticated attackers to trigger a denial-of-service condition on OpenSSL servers using a payload of only 11 bytes. The flaw stems from how the library handles TLS handshake headers, which contain a field declaring the size of the incoming message body. Vulnerable versions trust this header and allocate the requested memory immediately before the actual data arrives or is validated. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
