Commit 7fa04ecfe9 for openssl.org
commit 7fa04ecfe972d846f767eda2522c910228d6e677
Author: Ryan Hooper <ryanh@openssl.foundation>
Date: Tue Oct 6 10:08:36 2026 -0400
Document DTLS 1.3 KeyUpdate post-handshake record drop as a known issue
Assisted-by: Claude:claude-sonnet-5
Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Wed Oct 7 15:49:27 2026
Merged-from: https://github.com/openssl/openssl/pull/33123
diff --git a/NEWS.md b/NEWS.md
index b57adabc5a..97daa6ed74 100644
--- a/NEWS.md
+++ b/NEWS.md
@@ -77,6 +77,16 @@ This release adds the following new features:
* Initial support for the Elbrus2000 (`e2k`) architecture.
+Known issues in 4.1.0
+
+ * <https://github.com/openssl/openssl/issues/32878>
+ When a DTLS 1.3 KeyUpdate is received, all other outstanding
+ post-handshake records are dropped from the retransmission buffer.
+ This means post-handshake records still awaiting an ACK (such as a
+ NewSessionTicket) will no longer be retransmitted if the original
+ transmission is lost. A fix is in progress and planned for a future
+ release.
+
OpenSSL 4.0
-----------