Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-35189 | Excessive Memory Allocation in Relative CRLDP Processing | |
| CVE-2026-35191 | QUIC Unvalidated Amplification Credit may be Over Accounted | |
| CVE-2026-75806 | Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS | |
| CVE-2026-75804 | QUIC Connection-Level Flow Control is Not Enforced for Streams | |
| CVE-2026-75805 | NULL Pointer Dereference in CMP Client Revocation Response Handling | |
| CVE-2026-42772 | Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC | |
| CVE-2026-54873 | QUIC STREAM Fragment Metadata DoS | |
| CVE-2026-54872 | Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves | |
| CVE-2026-54875 | Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V | |
| CVE-2026-72897 | Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake | |
| CVE-2026-84782 | DTLS Retransmits Handshake Messages From a Stale Buffer Offset | |
| CVE-2026-84784 | QUIC: Unbounded RETIRE_CONNECTION_ID Backlog | |
| CVE-2026-84783 | Use-After-Free in X.509 Extension Cache Under Concurrent Use |
暂无评论