diff --git a/ChangeLog.d/chacha20_invalid_iv_len_fix.txt b/ChangeLog.d/chacha20_invalid_iv_len_fix.txt new file mode 100644 index 000000000..af35e2a00 --- /dev/null +++ b/ChangeLog.d/chacha20_invalid_iv_len_fix.txt @@ -0,0 +1,4 @@ +Default behavior changes + * mbedtls_cipher_set_iv will now fail with ChaCha20 and ChaCha20+Poly1305 + for IV lengths other than 12. The library was silently overwriting this + length with 12, but did not inform the caller about it. Fixes #4301.