diff --git a/ChangeLog b/ChangeLog index 182faecf7..0113d41d1 100644 --- a/ChangeLog +++ b/ChangeLog @@ -16,14 +16,11 @@ Bugfix Nicholas Wilson. Introduced in mbed TLS 2.1.4. #280 * Removed potential leak in mbedtls_rsa_rsassa_pkcs1_v15_sign(), found by JayaraghavendranK. #372 - -Change - * To avoid dropping an entire DTLS datagram if a single record in a datagram - is invalid, we now only drop the record and look at subsequent records (if - any are present) in the same datagram to avoid interoperability issues. - Previously the library was dropping the entire datagram, Where a record is - unexpected, the function mbedtls_ssl_read_record() will now return - MBEDTLS_ERR_SSL_UNEXPECTED_RECORD. + * Fix suboptimal handling of unexpected records that caused interop issues + with some peers over unreliable links. Avoid dropping an entire DTLS + datagram if a single record in a datagram is unexpected, instead only + drop the record and look at subsequent records (if any are present) in + the same datagram. Found by jeannotlapin. #345 = mbed TLS 2.1.3 released 2015-11-04