From 75bdaa35c39d2700795dc30808ee766ca518baae Mon Sep 17 00:00:00 2001 From: Ben Taylor <32939606+bjwtaylor@users.noreply.github.com> Date: Mon, 8 Jun 2026 13:28:07 +0100 Subject: [PATCH] Update ChangeLog to add CVE Co-authored-by: Gilles Peskine Signed-off-by: Ben Taylor <32939606+bjwtaylor@users.noreply.github.com> --- ChangeLog.d/1583-1584-ssl-transcript-errors.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ChangeLog.d/1583-1584-ssl-transcript-errors.txt b/ChangeLog.d/1583-1584-ssl-transcript-errors.txt index 3a18c76df9..ef092386a9 100644 --- a/ChangeLog.d/1583-1584-ssl-transcript-errors.txt +++ b/ChangeLog.d/1583-1584-ssl-transcript-errors.txt @@ -4,7 +4,7 @@ Security handshake to fail. This could allow a handshake to continue with a master secret that was not correctly bound to the handshake transcript, undermining the security guarantees of the extended master secret - extension. Report by Mathew Gretton-Dann. + extension. Report by Mathew Gretton-Dann. CVE-2026-50581 * Fix a TLS 1.3 server-side error-handling bug affecting session ticket generation. Under rare conditions, such as memory allocation failures while computing the resumption master secret, the server could issue