mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-10-02 06:57:24 +00:00
sig_algs: add ChangeLog
Signed-off-by: Janos Follath <[email protected]>
This commit is contained in:
@@ -0,0 +1,5 @@
|
|||||||
|
Security
|
||||||
|
* Fix a bug in the TLS 1.2 client's signature algorithm check, which caused
|
||||||
|
the client to accept server key exchange messages signed with a signature
|
||||||
|
algorithm explicitly disallowed by the client. Found and reported by
|
||||||
|
EFR-GmbH and M. Heuft of Security-Research-Consulting GmbH. CVE-2026-25834
|
||||||
Reference in New Issue
Block a user