Information Exposure Through Timing Discrepancy in OpenSSL - CVE-2026-54872
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to an observable timing discrepancy in generic elliptic-curve scalar multiplication when performing ECDSA or SM2 signing with curves lacking dedicated implementations. A remote attacker can measure signing times across many signatures to recover a private key.
The timing signal is small and is most pronounced for curves whose group order lies on a machine-word boundary.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-54872
openssl (Debian package) - update to 3.5.7-1~deb13u3