mbedtls/ChangeLog.d/padding-ct-changelog.txt
Dave Rodgman c3cb97896b Changelog for padding CT fixes
Signed-off-by: Dave Rodgman <dave.rodgman@arm.com>
2023-09-21 10:26:52 +01:00

7 lines
326 B
Plaintext

Security
* Fix non-constant-time behaviour in padding calculations in CBC
decryption, NIST SP 800-38F key wrapping, and RSAAES-OAEP decryption.
For CBC and RSAAES-OAEP, this may have been exploitable in a
padding oracle for a privileged local attacker with the ability to
observe memory access timings.