OpenSSL HollowByte - A DoS Hiding in 11 Bytes
-
This is an urgent request to the pfSense development team to review and assess the status of the OpenSSL HollowByte problem.
Here is the article about it.
-
And here is the answer from the authors (openssl).
I'll put my bets on the usual : Netgate is already aware.
[26.03.1-RELEASE][root@pfSense.bhf.tld]/root: openssl version OpenSSL 3.5.5 27 Jan 2026 (Library: OpenSSL 3.5.5 27 Jan 2026)If needed, the version pfSense uses will be rebuild, and we'll get a "3.5.7".
If you check for system packages yourself (see script on this forum) you will get a notification (mail, telegram, etc) when they are avaible.
You can install them then yourself :pkg update -
This post is deleted! -
Based on the CVE's I've read, it seems OpenSSL 3.0.16 running on CE 2.8.1 is unaffected.
[2.8.1-RELEASE][root@[redacted]]/root: openssl version OpenSSL 3.0.16 11 Feb 2025 (Library: OpenSSL 3.0.16 11 Feb 2025)https://vulners.com/cve/CVE-2026-34183
https://nvd.nist.gov/vuln/detail/CVE-2026-34183
https://app.opencve.io/cve/CVE-2026-34183It still amazes me that some people make some pfsense services public facing.
https://www.shodan.io/search?query=pfsense
-
@elvisimprsntr said in OpenSSL HollowByte - A DoS Hiding in 11 Bytes:
It still amazes me that some people make some pfsense services public facing.
Like OpenVPN for remote admining ?
-
@elvisimprsntr I block all shodan IPs before any of my open ports can be seen because there is no point for my IP to be in some db of ports at all.
But I did find it funny that the top port is snmp?
161 --> 1,585That seems insane to me.. The next highest port 80, is only 20.
-
@elvisimprsntr said in OpenSSL HollowByte - A DoS Hiding in 11 Bytes:
https://www.shodan.io/search?query=pfsense
Wait .... this does mean what I think it does ?
Like this part :
I make that a : "There are 3 pfSense routers out there that use 'Release 10.3', this means what ? pfSense 2.4.5 or something like that ?" and their GUI is accessible on the Internet ?
I'm wrong here, right ?
If not, ... well, what's beyond OMG ? -
@Gertjan said in OpenSSL HollowByte - A DoS Hiding in 11 Bytes:
pfSense 2.4.5 or something like that
means 2.3 version of pfsense. 2.4 was 11.1, 2.4.5 was 11.3
-
Yup that probably is what it means though. People who make the gui public also don't ever upgrade.

-
@stephenw10 "We're too small for someone to want to hack us"
-
@SteveITS "I am tired of managing my firewall, let the hackers do it." They can't steal my stuff if the firewall is down.

-
I made this thread expecting a professional, technical discussion from the community regarding a newly disclosed vulnerability. Instead, a serious inquiry about OpenSSL HollowByte has been derailed into off-topic jokes about outdated user configurations.
Since I do not have a direct way to contact the developers, I was hoping to get their attention here for an official assessment.
Can we please get this thread back on track?
-
@TCI_user I have flagged one the admins @stephenw10
-
@elvisimprsntr said in OpenSSL HollowByte - A DoS Hiding in 11 Bytes:
https://vulners.com/cve/CVE-2026-34183
Unclear if it is that issue. The linked article mentions there is no specific CVE for it.
If it is that then that's fixed in 26.07.
Edit: It's not that. Digging.....
-
@stephenw10 said in OpenSSL HollowByte - A DoS Hiding in 11 Bytes:
there is no specific CVE for it.
Seams that's the issue for standard change management https://cybersecuritynews.com/openssl-hollowbyte-vulnerability/ and https://my-ssl.com/learn/openssl-hollowbyte-vulnerability-2026
-
@stephenw10, here is the official report (no CVE):
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/In the above link you can find the Pull Requests that cover the fix (#30792, #30793, and #30794).
-
We pulled in 3.5.7 to be sure. Next beta will have it.
-
@stephenw10 so will a pkg update in 26.03 update to it, or will have to move to 26.07?
-
OpenSSL is in base so it can't be updated like that unfortunately. At least not yet.
-
@stephenw10 then how does update of unbound work, I ran pkg update the other day and a few things updated, and I noticed unbound went to 1.25.2 vs .1
isn't it part of the base pfsense - or do you mean part of freebsd base.
Privacy Policy · Cookie Policy