A critical denial-of-service vulnerability in the OpenSSL cryptographic library, disclosed by Okta, allows remote attackers to overwhelm server memory with a tiny data payload. Dubbed "HollowByte," the flaw affects versions 3.3.0, 3.3.1, and 3.3.2, and has been patched in OpenSSL 3.3.3.
Okta's Red Team reported that an attacker can send an 11-byte packet to a vulnerable server, triggering memory allocation of up to 131 KB. This amplification effect, where a small input causes disproportionate resource consumption, means even low-bandwidth attackers could disrupt high-traffic services.
OpenSSL is a foundational library for internet security, underpinning HTTPS, VPNs, and API communications. A vulnerability in such widely-deployed software creates a broad risk across numerous applications and services.
The disclosure highlights the value of proactive security research. Okta's coordinated reporting allowed the OpenSSL Project to develop and release a fix, giving administrators time to secure their systems.
IT teams should immediately audit infrastructure for the affected OpenSSL versions and upgrade to 3.3.3. Since OpenSSL is often bundled within other software, thorough dependency checks are essential. As an interim measure, enhanced monitoring and rate-limiting on public-facing TLS/SSL services can help mitigate risks.
The HollowByte flaw demonstrates how a small, efficient attack can disrupt systems. The low resource requirement for the attack makes it a concern for potential large-scale campaigns, emphasizing the importance of applying the available fix.
Okta 公開揭露 OpenSSL 密碼學庫中一個嚴重的拒絕服務漏洞,該漏洞允許遠端攻擊者透過極小的數據載荷癱瘓伺服器記憶體。此漏洞被暱稱為「HollowByte」,影響版本 3.3.0、3.3.1 及 3.3.2,已在 OpenSSL 3.3.3 中修補。
Okta 的紅隊報告指出,攻擊者可向存在漏洞的伺服器發送 11 字節的封包,觸發最多 131 KB 的記憶體分配。這種放大效應——即微小輸入導致不成比例的資源消耗——意味著即使頻寬有限的攻擊者也能癱瘓高流量服務。
OpenSSL 是網絡安全的基礎庫,支撐 HTTPS、VPN 及 API 通訊。如此廣泛部署的軟件出現漏洞,將對眾多應用程式及服務構成廣泛風險。
此次揭露凸顯主動安全研究的價值。Okta 的協調報告使 OpenSSL 專案得以開發並發布修補程式,給予管理員足夠時間加固系統。
資訊科技團隊應立即審計基礎設施,檢查受影響的 OpenSSL 版本並升級至 3.3.3。由於 OpenSSL 常內建於其他軟件中,徹底的依賴項檢查不可或缺。作為過渡措施,對公開的 TLS/SSL 服務加強監控及實施速率限制有助降低風險。
HollowByte 漏洞展示了一個小型、高效的攻擊如何癱瘓系統。該攻擊對資源需求極低,使其成為潛在大規模攻擊活動的關注點,突顯套用現有修補程式的重要性。
