diff --git a/ChangeLog.d/zeroize_key_buffers_before_free.txt b/ChangeLog.d/zeroize_key_buffers_before_free.txt new file mode 100644 index 000000000..ba5bae191 --- /dev/null +++ b/ChangeLog.d/zeroize_key_buffers_before_free.txt @@ -0,0 +1,4 @@ +Security + * Zeroize dynamically-allocated buffers used by the PSA Crypto key storage + module before freeing them. These buffers contain secret key material, and + could thus potentially leak the key through freed heap.