Keep only the X.509 part from the Changelog
Signed-off-by: Manuel Pégourié-Gonnard <manuel.pegourie-gonnard@arm.com>
diff --git a/ChangeLog.d/fix-string-to-names-store-named-data.txt b/ChangeLog.d/fix-string-to-names-store-named-data.txt
index 422ce07..e517cbb 100644
--- a/ChangeLog.d/fix-string-to-names-store-named-data.txt
+++ b/ChangeLog.d/fix-string-to-names-store-named-data.txt
@@ -1,12 +1,8 @@
Security
- * Fix a bug in mbedtls_asn1_store_named_data() where it would sometimes leave
- an item in the output list in an inconsistent state with val.p == NULL but
- val.len > 0. This impacts applications that call this function directly,
- or indirectly via mbedtls_x509_string_to_names() or one of the
- mbedtls_x509write_{crt,csr}_set_{subject,issuer}_name() functions. The
- inconsistent state of the output could then cause a NULL dereference either
- inside the same call to mbedtls_x509_string_to_names(), or in subsequent
+ * Fix a bug in mbedtls_x509_string_to_names() and the
+ mbedtls_x509write_{crt,csr}_set_{subject,issuer}_name() functions,
+ where some inputs would cause an inconsistent state to be reached, causing
+ a NULL dereference either in the function itself, or in subsequent
users of the output structure, such as mbedtls_x509_write_names(). This
only affects applications that create (as opposed to consume) X.509
- certificates, CSRs or CRLS, or that call mbedtls_asn1_store_named_data()
- directly. Found by Linh Le and Ngan Nguyen from Calif.
+ certificates, CSRs or CRLs. Found by Linh Le and Ngan Nguyen from Calif.