PT-2026-102650 · Linux Mint+1 · Linuxmint+1

·

CVE-2026-54872

·

Published

2026-09-29

·

Updated

2026-10-02

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description Generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations leaks information about the secret nonce through timing discrepancies. This occurs because curves without a dedicated constant-time implementation use BIGNUM operations that vary in execution time based on the value of the secret scalar. An attacker capable of measuring signing times across many signatures could potentially recover the private key using a lattice or Hidden Number Problem attack. This issue primarily affects applications using SM2 signing or ECDSA signing over Brainpool and other generic prime curves, particularly those whose group order lies on a machine-word boundary, such as brainpoolP384r1.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54872
SUSE-SU-2026:4412-1
SUSE-SU-2026:4413-1
SUSE-SU-2026:4414-1
SUSE-SU-2026:4419-1
USN-8847-1
USN-8847-2

Affected Products

Linuxmint
Ubuntu