From 2d0d3edb04ab0fa53e30e3cbdd114de9933d5361 Mon Sep 17 00:00:00 2001 From: Tomas Mraz Date: Tue, 7 Nov 2023 15:14:34 +0100 Subject: [PATCH] Sync CHANGES.md and NEWS.md with 3.1 branch Reviewed-by: Richard Levitte Reviewed-by: Matt Caswell (Merged from https://github.com/openssl/openssl/pull/22647) --- CHANGES.md | 8 ++++++-- NEWS.md | 6 +++++- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/CHANGES.md b/CHANGES.md index b2e4175cb8..408efa60ba 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -475,9 +475,13 @@ OpenSSL 3.2 OpenSSL 3.1 ----------- -### Changes between 3.1.3 and 3.1.4 [xx XXX xxxx] +### Changes between 3.1.4 and 3.1.5 [xx XXX xxxx] -* Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), + * none yet + +### Changes between 3.1.3 and 3.1.4 [24 Oct 2023] + + * Fix incorrect key and IV resizing issues when calling EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2() with OSSL_PARAM parameters that alter the key or IV length ([CVE-2023-5363]). diff --git a/NEWS.md b/NEWS.md index 141f9dcc66..975880c9fd 100644 --- a/NEWS.md +++ b/NEWS.md @@ -52,7 +52,11 @@ OpenSSL 3.2 OpenSSL 3.1 ----------- -### Major changes between OpenSSL 3.1.3 and OpenSSL 3.1.4 [under development] +### Major changes between OpenSSL 3.1.4 and OpenSSL 3.1.5 [under development] + + * none + +### Major changes between OpenSSL 3.1.3 and OpenSSL 3.1.4 [24 Oct 2023] * Mitigate incorrect resize handling for symmetric cipher keys and IVs. ([CVE-2023-5363])