mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-03-20 19:21:09 +01:00
Added CVE's to ChangeLogs
Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
This commit is contained in:
@@ -1,3 +1,4 @@
|
||||
Security
|
||||
* Fix a buffer overread in mbedtls_lms_import_public_key() when the input is
|
||||
less than 3 bytes. Reported by Linh Le and Ngan Nguyen from Calif.
|
||||
CVE-2025-49601
|
||||
|
||||
@@ -2,3 +2,4 @@ Security
|
||||
* Fix a vulnerability in LMS verification through which an adversary could
|
||||
get an invalid signature accepted if they could cause a hash accelerator
|
||||
to fail. Found and reported by Linh Le and Ngan Nguyen from Calif.
|
||||
CVE-2025-49600
|
||||
|
||||
Reference in New Issue
Block a user