Add ChangeLog entry
diff --git a/ChangeLog b/ChangeLog
index 8c82d08..652f013 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -2,6 +2,12 @@
 
 = mbed TLS x.x.x branch released xxxx-xx-xx
 
+Security
+   * Fix a timing variation in RSA PKCS#1 v1.5 decryption that could
+     lead to a Bleichenbacher-style attack. In TLS, this affects
+     RSA-based ciphersuites without DHE or ECDHE. Reported by Yuval Yarom,
+     Eyal Ronen, Adi Shamir, David Wong and Daniel Genkin.
+
 Bugfix
     * Fix failure in hmac_drbg in the benchmark sample application, when
       MBEDTLS_THREADING_C is defined. Found by TrinityTonic, #1095