Merge 'iotssl-566-double-free-restricted'

This commit is contained in:
Simon Butcher 2015-12-23 16:42:03 +00:00
commit 9c2626c641
2 changed files with 16 additions and 12 deletions

View file

@ -2,6 +2,11 @@ mbed TLS ChangeLog (Sorted per branch, date)
= mbed TLS 2.2.1 released 2015-12-xx
Security
* Fix potential double free when mbedtls_asn1_store_named_data() fails to
allocate memory. Only used for certificate generation, not triggerable
remotely in SSL/TLS. Found by Rafał Przywara. #367
Bugfix
* Fix over-restrictive length limit in GCM. Found by Andreas-N. #362