PT-2026-102652 · Openssl+2 · Openssl+2
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 4.0 through 4.0.2
OpenSSL versions 3.6 through 3.6.4
OpenSSL versions 3.5 through 3.5.8
OpenSSL versions 3.4 through 3.4.7
Description
On ARM64 and RISC-V platforms, the SM2 curve utilizes a scalar multiplication implementation that is not constant-time. Because conditional branches and table lookups are determined by the bits of the secret scalar, the execution time and cache-access patterns depend on the long-term private key during decryption or the per-signature nonce during signature generation. This creates a timing and cache side-channel that allows an attacker to learn information about the secret scalar.
Recommendations
Upgrade OpenSSL version 4.0 to 4.0.3.
Upgrade OpenSSL version 3.6 to 3.6.5.
Upgrade OpenSSL version 3.5 to 3.5.9.
Upgrade OpenSSL version 3.4 to 3.4.8.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Openssl
Ubuntu