mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-05-05 01:23:39 +02:00
5
ChangeLog.d/fix-aead-nonce.txt
Normal file
5
ChangeLog.d/fix-aead-nonce.txt
Normal file
@@ -0,0 +1,5 @@
|
||||
Security
|
||||
* In psa_aead_generate_nonce(), do not read back from the output buffer.
|
||||
This fixes a potential policy bypass or decryption oracle vulnerability
|
||||
if the output buffer is in memory that is shared with an untrusted
|
||||
application.
|
||||
Reference in New Issue
Block a user