OpenSSL have published a security advisory. Here's how it affects BoringSSL:
| CVE | Summary | Severity in OpenSSL | Impact to BoringSSL |
|---|---|---|---|
| CVE-2023-2975 | AES-SIV implementation ignores empty associated data entries | Low | Not affected; BoringSSL does not implement AES-SIV |