Vulnerability record · CVE-2016-6304 · published 26 September 2016
CVE-2016-6304: OpenSSL OCSP Status Request extension memory leak denial of service
OOpenssl · Openssl
OpenSSL versions before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a contain multiple memory leaks in t1_lib.c. A remote attacker can send large OCSP Status Request extensions during TLS handshakes to exhaust server memory. The flaw is a denial of service that can degrade or crash services relying on the affected OpenSSL library.
Description
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, and high EPSS percentile make this a significant availability risk despite no KEV listing.
What it is
OpenSSL versions before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a contain multiple memory leaks in t1_lib.c. A remote attacker can send large OCSP Status Request extensions during TLS handshakes to exhaust server memory. The flaw is a denial of service that can degrade or crash services relying on the affected OpenSSL library.
Impact
An unauthenticated remote attacker can consume process memory repeatedly, leading to resource exhaustion, service unavailability, or process termination. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network via TLS handshakes that include oversized OCSP Status Request extensions. No authentication or user interaction is required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.63029, 99.164th percentile), indicating elevated likelihood of exploitation activity, but the record does not confirm public exploit code.
What to do
- Upgrade OpenSSL to 1.0.1u, 1.0.2i, 1.1.0a or later, and apply vendor patches for Node.js and SUSE products.
- Where immediate patching is not possible, restrict or rate-limit TLS handshakes and monitor for abnormal memory growth in services using OpenSSL.
- Disable or limit OCSP stapling/status request handling if the deployment does not require it.
- Apply operating system and distribution vendor errata (Red Hat, SUSE, Juniper, IBM) that bundle the fixed OpenSSL version.
- Restart long-running TLS services periodically as a temporary containment measure until patched.
Detection
- Monitor OpenSSL-based service processes for sustained memory growth or OOM events correlated with TLS handshake volume.
- Inspect TLS handshake logs or packet captures for unusually large OCSP Status Request extensions.
- Alert on repeated connection attempts from single sources that trigger memory increases without completing normal application transactions.
- Track process restarts or crashes of TLS terminators and reverse proxies for unexplained availability loss.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6304 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6304), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.