diff --git a/releasenotes/notes/bump-curl-8.4.0-b99de8b63bcc92a4.yaml b/releasenotes/notes/bump-curl-8.4.0-b99de8b63bcc92a4.yaml new file mode 100644 index 00000000000000..7845011b6a5be3 --- /dev/null +++ b/releasenotes/notes/bump-curl-8.4.0-b99de8b63bcc92a4.yaml @@ -0,0 +1,11 @@ +# Each section from every release note are combined when the +# CHANGELOG.rst is rendered. So the text needs to be worded so that +# it does not depend on any information only available in another +# section. This may mean repeating some details, but each section +# must be readable independently of the other. +# +# Each section note must be formatted as reStructuredText. +--- +security: + - | + Bump embedded curl version to 8.4.0 to fix CVE-2023-38545 and CVE-2023-38546