### Changes between 3.3.2 and 3.3.3 [xx XXX xxxx]
+ * Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected.
+
+ Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a
+ server may fail to notice that the server was not authenticated, because
+ handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode
+ is set.
+
+ ([CVE-2024-12797])
+
+ *Viktor Dukhovni*
+
* Fixed timing side-channel in ECDSA signature computation.
There is a timing signal of around 300 nanoseconds when the top word of
### Major changes between OpenSSL 3.3.2 and OpenSSL 3.3.3 [under development]
OpenSSL 3.3.3 is a security patch release. The most severe CVE fixed in this
-release is Low.
+release is High.
This release incorporates the following bug fixes and mitigations:
+ * Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected.
+ ([CVE-2024-12797])
+
* Fixed timing side-channel in ECDSA signature computation.
([CVE-2024-13176])