changes and news entries for CVE-2023-5363

Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Hugo Landau <hlandau@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
This commit is contained in:
Pauli 2023-10-06 10:43:46 +11:00 committed by Matt Caswell
parent f3a7e6c057
commit 1e6e682ac2
2 changed files with 17 additions and 2 deletions

View File

@ -470,7 +470,15 @@ OpenSSL 3.2
OpenSSL 3.1
-----------
### Changes between 3.1.2 and 3.1.3 [xx XXX xxxx]
### Changes between 3.1.3 and 3.1.4 [xx XXX xxxx]
* Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(),
EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() with OSSL_PARAM parameters
that alter the key or IV length ([CVE-2023-5363]).
*Paul Dale*
### Changes between 3.1.2 and 3.1.3 [19 Sep 2023]
* Fix POLY1305 MAC implementation corrupting XMM registers on Windows.
@ -20288,6 +20296,7 @@ ndif
<!-- Links -->
[CVE-2023-5363]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5363
[CVE-2023-4807]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-4807
[CVE-2023-3817]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3817
[CVE-2023-3446]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3446

View File

@ -52,7 +52,12 @@ OpenSSL 3.2
OpenSSL 3.1
-----------
### Major changes between OpenSSL 3.1.2 and OpenSSL 3.1.3 [under development]
### Major changes between OpenSSL 3.1.3 and OpenSSL 3.1.4 [under development]
* Mitigate incorrect resize handling for symmetric cipher keys and IVs.
([CVE-2023-5363])
### Major changes between OpenSSL 3.1.2 and OpenSSL 3.1.3 [19 Sep 2023]
* Fix POLY1305 MAC implementation corrupting XMM registers on Windows
([CVE-2023-4807])
@ -1502,6 +1507,7 @@ OpenSSL 0.9.x
<!-- Links -->
[CVE-2023-5363]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5363
[CVE-2023-4807]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-4807
[CVE-2023-3817]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3817
[CVE-2023-3446]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3446