CVE-2026-54875
Received Received - Intake

Timing Side-Channel in OpenSSL SM2 Implementation

Vulnerability report for CVE-2026-54875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
openssl openssl From 4.0.0 (inc) to 4.0.3 (exc)
openssl openssl From 3.6.0 (inc) to 3.6.5 (exc)
openssl openssl From 3.5.0 (inc) to 3.5.9 (exc)
openssl openssl From 3.4.0 (inc) to 3.4.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves an optimized but non-constant-time implementation of scalar point multiplication used for SM2 private key operations on ARM64 and RISC-V platforms. The execution time and cache-access patterns depend on the secret scalar, allowing attackers to measure time or observe cache-line access to infer information about the private key during signing or decryption.

Detection Guidance

This vulnerability is specific to OpenSSL versions 4.0, 3.6, 3.5, and 3.4 on ARM64 and RISC-V platforms. Detection involves checking OpenSSL version and platform. Use 'openssl version' to verify version and 'uname -m' to check architecture. If using affected versions on ARM64 or RISC-V, the system is vulnerable.

Impact Analysis

An attacker could exploit this to learn sensitive information about your secret keys by analyzing timing or cache access patterns during SM2 operations. This could lead to private key compromise if the attacker gains sufficient data over time.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it relates to timing side-channel attacks rather than data protection failures. However, if exploited, it could lead to unauthorized access to cryptographic keys, potentially violating confidentiality requirements under these regulations.

Mitigation Strategies

Upgrade OpenSSL immediately. For OpenSSL 4.0 users, upgrade to 4.0.3. For 3.6 users, upgrade to 3.6.5. For 3.5 users, upgrade to 3.5.9. For 3.4 users, upgrade to 3.4.8. This resolves the timing side-channel issue in SM2 operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart