]> git.ipfire.org Git - thirdparty/openssl.git/commitdiff
Update CHANGES and NEWS for security release
authorNeil Horman <nhorman@openssl.org>
Tue, 11 Feb 2025 13:36:29 +0000 (08:36 -0500)
committerNeil Horman <nhorman@openssl.org>
Tue, 11 Feb 2025 13:40:40 +0000 (08:40 -0500)
Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
(cherry picked from commit cf9d6685fda656c07fab8527750284f4446a7372)

CHANGES.md
NEWS.md

index 9d1843dcf8b48ffe1decf69131f5c105b5d0e218..854fb975bea5948d1346972be1742fcaf30620fa 100644 (file)
@@ -29,6 +29,17 @@ OpenSSL 3.4
 
 ### Changes between 3.4.0 and 3.4.1 [xx XXX xxxx]
 
+ * Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected.
+
+   Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
+   server may fail to notice that the server was not authenticated, because
+   handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode
+   is set.
+
+   ([CVE-2024-12797])
+
+   *Viktor Dukhovni*
+
  * Fixed timing side-channel in ECDSA signature computation.
 
    There is a timing signal of around 300 nanoseconds when the top word of
diff --git a/NEWS.md b/NEWS.md
index 6f38b397c7065271c8cf9b82a6e7f9c5d902d16a..bec13b8806d1de957d9cbfd9a744451dcf9b147d 100644 (file)
--- a/NEWS.md
+++ b/NEWS.md
@@ -24,10 +24,14 @@ OpenSSL 3.4
 
 ### Major changes between OpenSSL 3.4.0 and OpenSSL 3.4.1 [under development]
 
-This release is in development.
+OpenSSL 3.4.1 is a security patch release. The most severe CVE fixed in this
+release is High.
 
 This release incorporates the following bug fixes and mitigations:
 
+  * Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected.
+    ([CVE-2024-12797])
+
   * Fixed timing side-channel in ECDSA signature computation.
     ([CVE-2024-13176])