OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 32%

By Swati Khandelwal12%

7/17/2026, 8:20:53 PM

BS Summary: This article contains 32 faulty reasoning types, including Negativity Bias, False Dilemma, and Recency Bias, with Confirmation Bias as the most egregious example at 18% saturation with 163 hits. Analysis detected 1,554 faulty-reasoning hits from 908 analyzed words, generating a BS Score of 40.8% and a BS Rank of 32% (14,587 of 21,202 articles). This article is better (less manipulative) than 68.80% of the article peer group.

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. 
On the glibc systems Okta tested, that memory is gone until the process restarts. 
OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. 
Okta's Red Team, which reported the denial-of-service bug and named it, published the details on Thursday. 
The fixed releases are OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, all dated June 9. 
Every release on those branches before the fixed ones has it. 
Nothing in a normal patch pipeline will point you at them: there is no identifier for a scanner to match and no advisory to read. 
The flaw is that OpenSSL took the attacker's word for it. 
Every TLS handshake message carries a 4-byte header, three bytes of which declare how long the body will be. 
Older versions grew the receive buffer to that declared size the moment the header landed, before a single byte of the body showed up, and before the handshake's own checks ran. 
For an inbound ClientHello the ceiling is 131 KB. 
Then the worker thread blocks, waiting on a body that never comes. 
No authentication, no session, no key exchange. 
The memory does not come back 
On its own, that is a connection-exhaustion attack, and those are as old as Slowloris. 
What makes HollowByte stick is glibc. 
When the attacker drops the connection, OpenSSL frees the buffer, but glibc holds small and medium chunks for reuse rather than returning them to the kernel. 
The attack varies the claimed size on every connection, and in Okta's tests, that was enough to stop the allocator from reusing what it freed. 
The heap fragments, resident set size climbs, and it stays climbed long after the attacker has gone. 
In Okta's NGINX testing, a 1 GB server was OOM-killed with 547 MB of memory frozen in fragments. 
On a 16 GB server, HollowByte locked up 25% of system memory without ever crossing the connection ceiling, which is why the Red Team says "standard connection-limiting defenses won't stop it". 
Those figures are Okta's own, and it published no exploit code alongside them. 
The Hacker News found no public proof-of-concept repository on GitHub as of July 18. 
OpenSSL decided this wasn't a vulnerability 
The pull request from Matt Caswell, who wrote the patch, puts it plainly: the security team chose to "handle this as a 'bug or hardening' only fix". 
OpenSSL's own security policy defines four severity tiers, Critical down to Low, and "bug or hardening" is not among them. 
Even a Low issue earns a CVE, a changelog note, and an entry on the vulnerabilities page. 
HollowByte has none of the three. 
The Hacker News found no mention of the fix in the release notes or in all 23 entries of OpenSSL's 4.0.1 changelog. 
OpenSSL has not said why. 
Here is the case for them: 131 KB per connection is small, every TLS server allocates memory per connection, and a bounded allocation is not a vulnerability. 
Okta's answer is that the memory never comes back. 
The Hacker News has asked OpenSSL why HollowByte was triaged below Low, and whether the fix reached the extended-support 1.1.1 and 1.0.2 branches. 
It has also asked Okta whether the fragmentation survives allocators other than glibc. 
This story will be updated with any response. 
The project's line is finer than it looks. 
In January, OpenSSL assigned CVE-2025-66199, rated Low, to a TLS 1.3 certificate-compression bug in which a peer-supplied length grew a heap buffer before validation, worth around 22 MiB per connection. 
That one needed four things to line up: certificate compression compiled in, a compression algorithm available, the extension negotiated, and, on servers, client certificates requested. 
HollowByte needs none of them. 
The same June 9 release assigned CVE-2026-34183, rated Moderate, to unbounded memory growth in the QUIC PATH_CHALLENGE handler. 
Both are memory-exhaustion DoS. 
Both got numbers. 
The release also closed 18 CVEs, including a High-severity use-after-free in PKCS7_verify(), so anyone running one of those upstream builds has the fix without being told. 
Downstream is worse. 
Red Hat's documented default is to backport rather than move the version, so a patched package still reports the version it was built from. 
What normally resolves that is the advisory and the OVAL feed, both keyed to CVE names. 
There is no CVE here to key on. 
That leaves the package changelog or the maintainer: ask whether they rebased on the June 9 release or took the patch, which is pull request 30792 for master and 4.0, 30793 for 3.6, 3.5, and 3.4, and 30794 for 3.0. 
If you build OpenSSL yourself, upgrade to the listed release and restart whatever loaded the old one. 
The fix covers TLS only. 
Caswell wrote on the pull request that DTLS was left alone because doing it properly would have been far more invasive, and that the project decided not to bother with it for now. 
The Hacker News compared OpenSSL's source at the 3.6.2 and 3.6.3 tags and found the DTLS handshake file byte-identical across the fix. 
In 4.0.1, the newest release, that path still sizes its buffer from the length the peer declares. 
OpenSSL has not classified that path or committed to fixing it. 
The release notes, the changelog, and the vulnerabilities page say nothing about it. 
The pull request does. 
Article reasoning-pattern comparisonThis article: 18.0%Swati Khandelwal: 2.5%The Hacker News: 2.0%Confirmation Bias18.0%This article: 0.3%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias0.3%This article: 10.8%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic10.8%This article: 2.1%Swati Khandelwal: 1.4%The Hacker News: 1.4%Representativeness Heuristic2.1%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias0.0%This article: 7.2%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias7.2%This article: 4.3%Swati Khandelwal: 2.9%The Hacker News: 2.8%Framing Effect4.3%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.1%Loss Aversion0.0%This article: 6.6%Swati Khandelwal: 0.6%The Hacker News: 0.6%Status Quo Bias6.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 2.4%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias2.4%This article: 1.3%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias1.3%This article: 16.0%Swati Khandelwal: 6.5%The Hacker News: 6.8%Negativity Bias16.0%This article: 1.4%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias1.4%This article: 1.2%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error1.2%This article: 3.6%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias3.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.4%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 11.1%Swati Khandelwal: 1.5%The Hacker News: 1.4%Recency Bias11.1%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.2%Primacy Effect0.0%This article: 2.3%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias2.3%This article: 1.2%Swati Khandelwal: 0.1%The Hacker News: 0.1%Ad Hominem1.2%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 10.4%Swati Khandelwal: 4.0%The Hacker News: 4.0%Appeal to Authority10.4%This article: 12.1%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma12.1%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.9%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.9%This article: 6.9%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization6.9%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 3.6%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question3.6%This article: 9.8%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)9.8%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.0%Tu Quoque0.0%This article: 6.2%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof6.2%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 3.4%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division3.4%This article: 3.4%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal3.4%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 4.5%Swati Khandelwal: 2.6%The Hacker News: 2.3%Ambiguity (Equivocation)4.5%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.3%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.3%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 3.6%Swati Khandelwal: 0.1%The Hacker News: 0.1%Special Pleading3.6%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 7.9%Swati Khandelwal: 1.1%The Hacker News: 1.4%Unattributed Quote7.9%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.0%Quote-first Misdirection0.0%This article: 5.4%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice5.4%This article: 0.9%Swati Khandelwal: 5.1%The Hacker News: 4.5%Indoctrination0.9%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 1.9%Swati Khandelwal: 0.4%The Hacker News: 2.9%Attempt to Sell a Product or S…1.9%

908 words analyzed.

Speakers

3speakers15%attributed speech774writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 11 words • 100.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageOkta's Red Team • 16 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 25 words • 100.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 6 words • 100.0% coverageMatt Caswell • 27 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 27 words • 100.0% coverageWriter's voice • 9 words • 0.0% coverageHacker News • 23 words • 0.0% coverageHacker News • 13 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 40 words • 0.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 5 words • 0.0% coverageMatt Caswell • 33 words • 0.0% coverageHacker News • 22 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverage
Selected voice

Matt Caswell

100%flagged-word coverage
60 attributed words45% of attributed speech87% writer coverage
0%22.5%45.0%Unattributed Quote+39.2 ptsWriter: 5.8%Matt Caswell: 45.0%45.0%Biased Writer Voice-6.3 ptsWriter: 6.3%Matt Caswell: 0.0%0.0%Attempt to Sell a Product -2.2 ptsWriter: 2.2%Matt Caswell: 0.0%0.0%Indoctrination-1.0 ptsWriter: 1.0%Matt Caswell: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.