Add ChangeLog entry for PKCS#7 side channel fix

Signed-off-by: David Horstmann <david.horstmann@arm.com>
diff --git a/ChangeLog.d/pkcs7-padding-side-channel-fix.txt b/ChangeLog.d/pkcs7-padding-side-channel-fix.txt
new file mode 100644
index 0000000..f34c095
--- /dev/null
+++ b/ChangeLog.d/pkcs7-padding-side-channel-fix.txt
@@ -0,0 +1,4 @@
+Security
+   * Fix a timing side channel in the implementation of PKCS#7 padding
+     which would allow an attacker who can request decryption of arbitrary
+     ciphertexts to recover the last byte of each block of the plaintext.