From 2d666646bace4de2fce0f8dd9f95df560dd55f73 Mon Sep 17 00:00:00 2001 From: Gilles Peskine Date: Thu, 7 Aug 2025 23:07:31 +0200 Subject: [PATCH] Changelog entry for PSA CBC-PKCS7 padding oracle fix Signed-off-by: Gilles Peskine --- ChangeLog.d/pkcs7-padding-error-leak.txt | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 ChangeLog.d/pkcs7-padding-error-leak.txt diff --git a/ChangeLog.d/pkcs7-padding-error-leak.txt b/ChangeLog.d/pkcs7-padding-error-leak.txt new file mode 100644 index 0000000000..5d204d5bef --- /dev/null +++ b/ChangeLog.d/pkcs7-padding-error-leak.txt @@ -0,0 +1,5 @@ +Security + * Fix a timing side channel in CBC-PKCS7 decryption that could + allow an attacker who can submit chosen ciphertexts to recover + some plaintexts through a timing-based padding oracle attack. + Credits to Beat Heeb from Oberon microsystems AG. CVE-TODO