doc: security: Add CVE-2021-3581 to docs

Update release notes for 2.6, and the vulnerabilities page to mention
CVE-2021-3581.  This CVE is under embargo until Sept 4, 2021.

Signed-off-by: David Brown <david.brown@linaro.org>
diff --git a/doc/releases/release-notes-2.6.rst b/doc/releases/release-notes-2.6.rst
index f997528..7a71119 100644
--- a/doc/releases/release-notes-2.6.rst
+++ b/doc/releases/release-notes-2.6.rst
@@ -31,6 +31,8 @@
 More detailed information can be found in:
 https://docs.zephyrproject.org/latest/security/vulnerabilities.html
 
+* CVE-2021-3581: Under embargo until 2021-09-04
+
 Known issues
 ************
 
diff --git a/doc/security/vulnerabilities.rst b/doc/security/vulnerabilities.rst
index fe67630..906e0c9 100644
--- a/doc/security/vulnerabilities.rst
+++ b/doc/security/vulnerabilities.rst
@@ -820,3 +820,8 @@
   <https://zephyrprojectsec.atlassian.net/browse/ZEPSEC-116>`_
 
 - This issue has not been fixed.
+
+CVE-2021-3581
+-------------
+
+Under embargo until 2021/09/04