Changelog: Add entry for prime validation fix
diff --git a/ChangeLog b/ChangeLog
index 8c82d08..2667943 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -14,6 +14,20 @@
test the handling of large packets and small packets on the client side
in the same way as on the server side.
+Security
+ * Fix mbedtls_mpi_is_prime() to use more rounds of probabilistic testing. The
+ previous settings for the number of rounds made it practical for an
+ adversary to construct non-primes that would be erroneously accepted as
+ primes with high probability. This does not have an impact on the
+ security of TLS, but can matter in other contexts with potentially
+ adversarially-chosen numbers that should be prime and can be validated.
+ For example, the number of rounds was enough to securely generate RSA key
+ pairs or Diffie-Hellman parameters, but was insufficient to validate
+ Diffie-Hellman parameters properly.
+ See "Prime and Prejudice" by by Martin R. Albrecht and Jake Massimo and
+ Kenneth G. Paterson and Juraj Somorovsky.
+
+
= mbed TLS 2.1.15 branch released 2018-08-31
Security