mbedtls/ChangeLog.d/fix-legacy-compression-issue.txt
Waleed Elmelegy b5df9d8b65 Add chanelog entry for fixing legacy comprssion methods issue
Signed-off-by: Waleed Elmelegy <waleed.elmelegy@arm.com>
2024-08-22 16:10:10 +00:00

8 lines
507 B
Plaintext

Bugfix
* Fix an issue where ssl_tls13_parse_client_hello() assumed legacy_compression_methods
length would always be zero, which is true for TLS 1.3. However, with TLS 1.3 enabled
by default, all ClientHello requests (including TLS 1.2 requests) are initially
processed by ssl_tls13_parse_client_hello() before being passed to the TLS 1.2
parsing function. This caused an issue where legacy_compression_methods
might not be zero for TLS 1.2 requests, as it is processed earlier.