Extended attributions & CVE

Signed-off-by: Minos Galanakis <minos.galanakis@arm.com>
This commit is contained in:
Minos Galanakis
2026-03-26 14:51:04 +00:00
parent f3f27070a6
commit feb0dd04ba
2 changed files with 3 additions and 4 deletions

View File

@@ -4,5 +4,5 @@ Security
mbedtls_ssl_context_load() has been updated to clarify the responsibility
of the application to preserve the confidentiality and integrity of
serialized data, mitigating the risk of misuse of these APIs.
Credit to Haruto Kimura (Stella) for highlighting risks associated with
tampered serialized data.
Credit to Haruto Kimura (Stella) and Eva Crystal (0xiviel) for
highlighting risks associated with tampered serialized data.

View File

@@ -2,5 +2,4 @@ Security
* Fix a limited buffer underflow in x509_inet_pton_ipv6(). In rare cases
(e.g. on platforms with memory protection when the overread crosses page
boundary) this could lead to DoS. Found and reported by Haruto Kimura
(Stella).
CVE-2026-25833
(Stella). CVE-2026-25833