From 0086f8626a7fbd82625d6696b621d1e2ad56edad Mon Sep 17 00:00:00 2001 From: Janos Follath Date: Wed, 15 Mar 2023 13:31:48 +0000 Subject: [PATCH] Add changelog entry PR7083 silently fixed a security vulnerability in public, this commit adds a changelog entry for it. Signed-off-by: Janos Follath --- ChangeLog.d/fix-overread-in-tls13-debug.txt | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 ChangeLog.d/fix-overread-in-tls13-debug.txt diff --git a/ChangeLog.d/fix-overread-in-tls13-debug.txt b/ChangeLog.d/fix-overread-in-tls13-debug.txt new file mode 100644 index 000000000..e089ce161 --- /dev/null +++ b/ChangeLog.d/fix-overread-in-tls13-debug.txt @@ -0,0 +1,3 @@ +Security + * Fix a potential heap buffer overread in TLS 1.3 client-side when + MBEDTLS_DEBUG_C is enabled. This may result in an application crash.