From: Tomas Mraz Date: Tue, 7 Nov 2023 14:14:34 +0000 (+0100) Subject: Sync CHANGES.md and NEWS.md with 3.1 branch X-Git-Tag: openssl-3.3.0-alpha1~647 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=96ee2c38ad9b1c878a11bf629499867777c18055;p=thirdparty%2Fopenssl.git Sync CHANGES.md and NEWS.md with 3.1 branch Reviewed-by: Richard Levitte Reviewed-by: Matt Caswell (Merged from https://github.com/openssl/openssl/pull/22647) (cherry picked from commit 2d0d3edb04ab0fa53e30e3cbdd114de9933d5361) --- diff --git a/CHANGES.md b/CHANGES.md index 029589c7d39..98ac35500f6 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -486,9 +486,13 @@ OpenSSL 3.2 OpenSSL 3.1 ----------- -### Changes between 3.1.3 and 3.1.4 [xx XXX xxxx] +### Changes between 3.1.4 and 3.1.5 [xx XXX xxxx] -* Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), + * none yet + +### Changes between 3.1.3 and 3.1.4 [24 Oct 2023] + + * Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() with OSSL_PARAM parameters that alter the key or IV length ([CVE-2023-5363]). diff --git a/NEWS.md b/NEWS.md index b19d8e3d2c0..5808f805a08 100644 --- a/NEWS.md +++ b/NEWS.md @@ -60,7 +60,11 @@ OpenSSL 3.2 OpenSSL 3.1 ----------- -### Major changes between OpenSSL 3.1.3 and OpenSSL 3.1.4 [under development] +### Major changes between OpenSSL 3.1.4 and OpenSSL 3.1.5 [under development] + + * none + +### Major changes between OpenSSL 3.1.3 and OpenSSL 3.1.4 [24 Oct 2023] * Mitigate incorrect resize handling for symmetric cipher keys and IVs. ([CVE-2023-5363])