OpenSSL HollowByte patch release
Security Patch Release
Summary
Hide ▲
Show ▼
The OpenSSL team silently fixed HollowByte, a no-CVE DoS flaw in OpenSSL servers, and backported the patch to older releases. The fix lands in OpenSSL 4.0.1 and was also backported to 3.6.3, 3.5.7, 3.4.6, and 3.0.21. Organizations running OpenSSL-backed services should move to a fixed release because the bug can be triggered with a tiny 11-byte payload.
Related Happenings
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch Release
H score39
First: 30.04.2026 16:54
Last: 30.04.2026 16:54
Sources 1
About this happening:
Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch ReleaseAbout this happening: Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
WolfSSL security patch release (CVE-2026-5194)
Security Patch Release
H score31
First: 13.04.2026 22:56
Last: 13.04.2026 22:56
Sources 1
About this happening:
The wolfSSL project released version 5.9.1 to fix CVE-2026-5194, a cryptographic validation flaw that could let vulnerable deployments accept forged certificates. The...
WolfSSL security patch release (CVE-2026-5194)
Security Patch ReleaseAbout this happening: The wolfSSL project released version 5.9.1 to fix CVE-2026-5194, a cryptographic validation flaw that could let vulnerable deployments accept forged certificates. The...
OpenSSL coordinated security update (12 vulnerabilities)
Security Patch Release
H score28
First: 28.01.2026 18:45
Last: 28.01.2026 18:45
Sources 1
About this happening:
A January 2026 coordinated security update fixed 12 previously unknown vulnerabilities in OpenSSL, a widely used cryptographic library. The release matters because Ope...
OpenSSL coordinated security update (12 vulnerabilities)
Security Patch ReleaseAbout this happening: A January 2026 coordinated security update fixed 12 previously unknown vulnerabilities in OpenSSL, a widely used cryptographic library. The release matters because Ope...
Timeline
-
17.07.2026 20:56 3 articles · 13d ago
OpenSSL silently fixes HollowByte and backports the patch to older releases
Mitigation Patch UpdateOkta’s Red Team described HollowByte, an unauthenticated DoS flaw in OpenSSL servers that can be triggered with an 11-byte TLS payload and can drive memory exhaustion and heap bloat; the OpenSSL team silently fixed the issue and backported the patch to OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21.
Show sources
- HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload — www.bleepingcomputer.com — 17.07.2026 20:56
- HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload — www.bleepingcomputer.com — 17.07.2026 20:56
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — thehackernews.com — 17.07.2026 23:20