[CVE-2022-38177][v9_11] ecdsa verify leak

The CHANGES entry is added because it's easy to do, but the release note isn't, as it requires adding a new doc/arm/notes-9.11.38.xml file, which would suggest a new release, which won't happen.

Order of battle:

Closes #3487 (closed)

