The HollowByte OpenSSL vulnerability leads to DoS conditions via successive buffer pre-allocations that are not freed.
The OpenSSL maintainers have quietly closed a denial-of-service vulnerability. Okta calls it “HollowByte”. In a recent blog ...
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.