PT-2026-102652 · Openssl+2 · Openssl+2

·

CVE-2026-54875

·

Published

2026-09-29

·

Updated

2026-10-02

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 4.0 through 4.0.2 OpenSSL versions 3.6 through 3.6.4 OpenSSL versions 3.5 through 3.5.8 OpenSSL versions 3.4 through 3.4.7
Description On ARM64 and RISC-V platforms, the SM2 curve utilizes a scalar multiplication implementation that is not constant-time. Because conditional branches and table lookups are determined by the bits of the secret scalar, the execution time and cache-access patterns depend on the long-term private key during decryption or the per-signature nonce during signature generation. This creates a timing and cache side-channel that allows an attacker to learn information about the secret scalar.
Recommendations Upgrade OpenSSL version 4.0 to 4.0.3. Upgrade OpenSSL version 3.6 to 3.6.5. Upgrade OpenSSL version 3.5 to 3.5.9. Upgrade OpenSSL version 3.4 to 3.4.8.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54875
SUSE-SU-2026:4414-1
USN-8847-1

Affected Products

Linuxmint
Openssl
Ubuntu