mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-04-13 15:42:26 +02:00
sig_algs: add ChangeLog
Signed-off-by: Janos Follath <janos.follath@arm.com>
This commit is contained in:
5
ChangeLog.d/sig_algs_check.txt
Normal file
5
ChangeLog.d/sig_algs_check.txt
Normal file
@@ -0,0 +1,5 @@
|
||||
Security
|
||||
* Fix a bug in the TLS 1.2 client's signature algorithm check, which caused
|
||||
the client to accept server key exchange messages signed with a signature
|
||||
algorithm explicitly disallowed by the client. Found and reported by
|
||||
EFR-GmbH and M. Heuft of Security-Research-Consulting GmbH. CVE-2026-25834
|
||||
Reference in New Issue
Block a user