Added changelog for check return of merkle leaf

Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
This commit is contained in:
Minos Galanakis
2025-06-02 14:38:55 +01:00
parent 3444757ac4
commit f84bc3f592

View File

@@ -0,0 +1,4 @@
Security
* Fix a vulnerability in LMS verification through which an adversary could
get an invalid signature accepted if they could cause a hash accelerator
to fail. Found and reported by Linh Le and Ngan Nguyen from Calif.