diff --git a/ChangeLog b/ChangeLog
index e199682eab..1e3614b9b3 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -5,6 +5,8 @@ mbed TLS ChangeLog (Sorted per branch, date)
 Bugfix
    * Fix ssl_parse_record_header() to silently discard invalid DTLS records
      as recommended in RFC 6347 Section 4.1.2.7.
+   * Add size-checks for record and handshake message content, securing
+     fragile yet non-exploitable code-paths.
 
 = mbed TLS 2.6.0 branch released 2017-08-10