mirror of https://github.com/openssl/openssl.git
Update CHANGES and NEWS for security release
Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
(cherry picked from commit cf9d6685fd
)
This commit is contained in:
parent
d3d16e36cc
commit
f2a1024cdc
11
CHANGES.md
11
CHANGES.md
|
@ -29,6 +29,17 @@ OpenSSL 3.4
|
||||||
|
|
||||||
### Changes between 3.4.0 and 3.4.1 [xx XXX xxxx]
|
### Changes between 3.4.0 and 3.4.1 [xx XXX xxxx]
|
||||||
|
|
||||||
|
* Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected.
|
||||||
|
|
||||||
|
Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
|
||||||
|
server may fail to notice that the server was not authenticated, because
|
||||||
|
handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode
|
||||||
|
is set.
|
||||||
|
|
||||||
|
([CVE-2024-12797])
|
||||||
|
|
||||||
|
*Viktor Dukhovni*
|
||||||
|
|
||||||
* Fixed timing side-channel in ECDSA signature computation.
|
* Fixed timing side-channel in ECDSA signature computation.
|
||||||
|
|
||||||
There is a timing signal of around 300 nanoseconds when the top word of
|
There is a timing signal of around 300 nanoseconds when the top word of
|
||||||
|
|
6
NEWS.md
6
NEWS.md
|
@ -24,10 +24,14 @@ OpenSSL 3.4
|
||||||
|
|
||||||
### Major changes between OpenSSL 3.4.0 and OpenSSL 3.4.1 [under development]
|
### Major changes between OpenSSL 3.4.0 and OpenSSL 3.4.1 [under development]
|
||||||
|
|
||||||
This release is in development.
|
OpenSSL 3.4.1 is a security patch release. The most severe CVE fixed in this
|
||||||
|
release is High.
|
||||||
|
|
||||||
This release incorporates the following bug fixes and mitigations:
|
This release incorporates the following bug fixes and mitigations:
|
||||||
|
|
||||||
|
* Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected.
|
||||||
|
([CVE-2024-12797])
|
||||||
|
|
||||||
* Fixed timing side-channel in ECDSA signature computation.
|
* Fixed timing side-channel in ECDSA signature computation.
|
||||||
([CVE-2024-13176])
|
([CVE-2024-13176])
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue