Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35189 | Excessive Memory Allocation in Relative CRLDP Processing | |
| CVE-2026-35191 | QUIC Unvalidated Amplification Credit may be Over Accounted | |
| CVE-2026-75806 | Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS | |
| CVE-2026-75804 | QUIC Connection-Level Flow Control is Not Enforced for Streams | |
| CVE-2026-75805 | NULL Pointer Dereference in CMP Client Revocation Response Handling | |
| CVE-2026-42772 | Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC | |
| CVE-2026-54873 | QUIC STREAM Fragment Metadata DoS | |
| CVE-2026-54872 | Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves | |
| CVE-2026-77696 | Timing Side-Channel in SM2 Signature Generation | |
| CVE-2026-72897 | Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake | |
| CVE-2026-84782 | DTLS Retransmits Handshake Messages From a Stale Buffer Offset | |
| CVE-2026-84784 | QUIC: Unbounded RETIRE_CONNECTION_ID Backlog | |
| CVE-2026-84783 | Use-After-Free in X.509 Extension Cache Under Concurrent Use |
No comments yet