A recently discovered vulnerability in OpenSSL, termed 'HollowByte', can allow attackers to cause denial of service (DoS) by exploiting a buffer pre-allocation flaw. This issue, uncovered by Okta's red team, can be triggered using an 11-byte malicious payload, leading to significant memory exhaustion on servers running various applications that utilize OpenSSL. The vulnerability exploits how older OpenSSL versions pre-allocate buffers based purely on the declared size in handshake messages.
Affected systems include those using Apache, NGINX, and others unless they upgrade to patched versions of OpenSSL. Patches have been included in version 4.0.1 and backported to earlier versions.