diff --git a/ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt b/ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt new file mode 100644 index 0000000000..9feca99ba7 --- /dev/null +++ b/ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt @@ -0,0 +1,4 @@ +Security + * Fix a vulnerability in LMS verification through which an adversary could + get an invalid signature accepted if they could cause a hash accelerator + to fail. Found and reported by Linh Le and Ngan Nguyen from Calif.