From: Neil Horman Date: Tue, 11 Feb 2025 13:36:29 +0000 (-0500) Subject: Update CHANGES and NEWS for security release X-Git-Tag: openssl-3.2.4~3 X-Git-Url: http://git.ipfire.org/gitweb/gitweb.cgi?a=commitdiff_plain;h=99d9e3792d4fa4211b2b99fd6fb3b9a47d55d671;p=thirdparty%2Fopenssl.git Update CHANGES and NEWS for security release Reviewed-by: Tomas Mraz Reviewed-by: Matt Caswell (cherry picked from commit f86bfcc4e0408a5a1abaeb04463b27264eb94063) --- diff --git a/CHANGES.md b/CHANGES.md index 41db454b2c5..9da5c7a057a 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -27,6 +27,17 @@ OpenSSL 3.2 ### Changes between 3.2.3 and 3.2.4 [xx XXX xxxx] + * Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. + + Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a + server may fail to notice that the server was not authenticated, because + handshakes don't abort as expected when the SSL_VERIFY_PEER verification mode + is set. + + ([CVE-2024-12797]) + + *Viktor Dukhovni* + * Fixed timing side-channel in ECDSA signature computation. There is a timing signal of around 300 nanoseconds when the top word of diff --git a/NEWS.md b/NEWS.md index 9561d028860..9f2f6e19c33 100644 --- a/NEWS.md +++ b/NEWS.md @@ -23,10 +23,13 @@ OpenSSL 3.2 ### Major changes between OpenSSL 3.2.3 and OpenSSL 3.2.4 [under development] OpenSSL 3.2.4 is a security patch release. The most severe CVE fixed in this -release is Low. +release is High. This release incorporates the following bug fixes and mitigations: + * Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. + ([CVE-2024-12797]) + * Fixed timing side-channel in ECDSA signature computation. ([CVE-2024-13176])