From f84bc3f59246c6077664d7a32278836103dccb80 Mon Sep 17 00:00:00 2001 From: Minos Galanakis Date: Mon, 2 Jun 2025 14:38:55 +0100 Subject: [PATCH] Added changelog for check return of merkle leaf Signed-off-by: Minos Galanakis --- ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt diff --git a/ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt b/ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt new file mode 100644 index 0000000000..9feca99ba7 --- /dev/null +++ b/ChangeLog.d/1353_lms_check_return_of_merkle_leaf.txt @@ -0,0 +1,4 @@ +Security + * Fix a vulnerability in LMS verification through which an adversary could + get an invalid signature accepted if they could cause a hash accelerator + to fail. Found and reported by Linh Le and Ngan Nguyen from Calif.