Commit 7fa04ecfe9 for openssl.org

commit 7fa04ecfe972d846f767eda2522c910228d6e677
Author: Ryan Hooper <ryanh@openssl.foundation>
Date:   Tue Oct 6 10:08:36 2026 -0400

    Document DTLS 1.3 KeyUpdate post-handshake record drop as a known issue

    Assisted-by: Claude:claude-sonnet-5
    Reviewed-by: Matt Caswell <matt@openssl.foundation>
    Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
    Merge-date: Wed Oct  7 15:49:27 2026
    Merged-from: https://github.com/openssl/openssl/pull/33123

diff --git a/NEWS.md b/NEWS.md
index b57adabc5a..97daa6ed74 100644
--- a/NEWS.md
+++ b/NEWS.md
@@ -77,6 +77,16 @@ This release adds the following new features:

   * Initial support for the Elbrus2000 (`e2k`) architecture.

+Known issues in 4.1.0
+
+  * <https://github.com/openssl/openssl/issues/32878>
+    When a DTLS 1.3 KeyUpdate is received, all other outstanding
+    post-handshake records are dropped from the retransmission buffer.
+    This means post-handshake records still awaiting an ACK (such as a
+    NewSessionTicket) will no longer be retransmitted if the original
+    transmission is lost. A fix is in progress and planned for a future
+    release.
+
 OpenSSL 4.0
 -----------