Information Exposure Through Timing Discrepancy in OpenSSL - CVE-2026-54875
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose secret scalar information.
The vulnerability exists due to an observable timing discrepancy in optimized SM2 scalar multiplication on ARM64 and RISC-V when performing SM2 signing or decryption. A remote attacker can measure operation times or observe cache-line access patterns to disclose secret scalar information.
The issue affects AArch64 and RISC-V platforms.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-54875
openssl (Debian package) - update to 3.5.7-1~deb13u3