Merge pull request #1085 from daverodgman/update-ct-changelog-2.28

Backport 2.28: Update padding const-time fix changelog
diff --git a/ChangeLog.d/padding-ct-changelog.txt b/ChangeLog.d/padding-ct-changelog.txt
index e3d3424..3e2c7e2 100644
--- a/ChangeLog.d/padding-ct-changelog.txt
+++ b/ChangeLog.d/padding-ct-changelog.txt
@@ -1,6 +1,6 @@
 Security
    * Improve padding calculations in CBC decryption, NIST key unwrapping and
      RSA OAEP decryption. With the previous implementation, some compilers
-     (notably recent versions of Clang) could produce non-constant time code,
-     which could allow a padding oracle attack if the attacker has access to
-     precise timing measurements.
+     (notably recent versions of Clang and IAR) could produce non-constant
+     time code, which could allow a padding oracle attack if the attacker
+     has access to precise timing measurements.