Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54875— Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V

Quick assessment

Affected
OpenSSL OpenSSL
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54875

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
Source: CVE Program / CVE List V5
Vulnerability Description
Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
通过时间差异性导致的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenSSL OpenSSL 4.0.0 ~ 4.0.3 -

II. Public POCs for CVE-2026-54875

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54875

请登录查看更多情报信息。

Other References for CVE-2026-54875 (5)

Same Patch Batch · OpenSSL · 2026-09-29 · 14 CVEs total

CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing
CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling
CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use

IV. Related Vulnerabilities

V. Comments for CVE-2026-54875

No comments yet


Leave a comment