Observable Timing Discrepancy in OpenSSL for SM2 Operations on ARM64 and RISC-V
CVE-2026-54875
Currently unrated
What is CVE-2026-54875?
A vulnerability exists in the scalar point multiplication implementation used for SM2 private key operations in OpenSSL on ARM64 and RISC-V architectures. Due to non-constant time execution, this implementation is susceptible to timing and cache side-channel attacks. An attacker could exploit these discrepancies to infer information about the secret scalar, making the private key vulnerable during signing and decryption processes. Users of OpenSSL version 4.0.0 to 4.0.2, 3.6.0 to 3.6.4, 3.5.0 to 3.5.8, and 3.4.0 to 3.4.7 are recommended to upgrade to their respective patched versions for enhanced security.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9