summaryrefslogtreecommitdiffstats
path: root/NEWS.md
diff options
context:
space:
mode:
authorPauli <pauli@openssl.org>2023-10-06 10:43:46 +1100
committerMatt Caswell <matt@openssl.org>2023-10-24 14:32:24 +0100
commit1e6e682ac27abd9d028f5a7876f7da1a176c175a (patch)
tree66cf3c04bed70743dcf3841fefa0212ae8f4e633 /NEWS.md
parentf3a7e6c057b5054aa05710f3d528b92e3e885268 (diff)
changes and news entries for CVE-2023-5363
Reviewed-by: Tomas Mraz <tomas@openssl.org> Reviewed-by: Hugo Landau <hlandau@openssl.org> Reviewed-by: Matt Caswell <matt@openssl.org>
Diffstat (limited to 'NEWS.md')
-rw-r--r--NEWS.md8
1 files changed, 7 insertions, 1 deletions
diff --git a/NEWS.md b/NEWS.md
index d0312961df..141f9dcc66 100644
--- a/NEWS.md
+++ b/NEWS.md
@@ -52,7 +52,12 @@ OpenSSL 3.2
OpenSSL 3.1
-----------
-### Major changes between OpenSSL 3.1.2 and OpenSSL 3.1.3 [under development]
+### Major changes between OpenSSL 3.1.3 and OpenSSL 3.1.4 [under development]
+
+ * Mitigate incorrect resize handling for symmetric cipher keys and IVs.
+ ([CVE-2023-5363])
+
+### Major changes between OpenSSL 3.1.2 and OpenSSL 3.1.3 [19 Sep 2023]
* Fix POLY1305 MAC implementation corrupting XMM registers on Windows
([CVE-2023-4807])
@@ -1502,6 +1507,7 @@ OpenSSL 0.9.x
<!-- Links -->
+[CVE-2023-5363]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5363
[CVE-2023-4807]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-4807
[CVE-2023-3817]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3817
[CVE-2023-3446]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3446