Database/Kernel, userspace & hypervisor
OpenSSL: non-constant-time SM2 point multiplication on AArch64 and RISC-V leaks key bits via timing and cache
Impact
The optimized SM2 scalar multiplication used on ARM64 and RISC-V branches and indexes tables according to secret bits, so execution time and cache-line access depend on the long-term private key during SM2 decryption and on the per-signature nonce during signing. An attacker co-resident on the same physical host - a neighbouring tenant on an Arm-based head node or Grace-class GPU server - who can time or observe cache behaviour of those operations can recover information about the secret scalar. Practical only where SM2 is actually in use, which for most operators is nowhere; TLS with ECDSA/RSA and the FIPS module are unaffected. Treat this as relevant if you run SM2 certificates or a Chinese-market cryptographic profile on Arm or RISC-V hardware.
Who can reach it
An attacker able to measure timing of, or observe cache-line access patterns for, SM2 signing or decryption on an affected AArch64 or RISC-V host - in practice local or co-resident on the machine performing the SM2 operation. No credentials on the target service are stated as required.
What to do
Upgrade OpenSSL: 4.0 users to 4.0.3, 3.6 to 3.6.5, 3.5 to 3.5.9, 3.4 to 3.4.8. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected. Distro packages are the usual path; every daemon linked against the shared library has to be restarted (or the node rebooted) before the new code is in use - no firmware or node drain needed. Statically linked appliances and containers need rebuilt images.
References
Related entries
- OpenSSH: heap out-of-bounds read during GSSAPI indicator cleanup crashes the authentication pathCVE-2026-55654 · OpenSSH sshd (GSSAPI auth-indicator cleanup)Low
- strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memoryCVE-2026-78124 · strongSwan openssl plugin (PKCS#7 certificate enumeration)Low
- OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysCVE-2026-73281 · OpenSSH ssh-agent (agent locking vs session-bind@openssh.com extension)Low
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingCVE-2018-20855 · Linux kernel mlx5_ib (create QP response)Low
- Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selection: Setting Speculative Store Bypass Disable on AMD FamilyCVE-2022-42336 · Xen on AMD Family 17h / Hygon Family 18h - guest SSBD selectionLow
- OpenSSH sshd: restrict keyword in authorized_keys did not cover tunnel forwardingCVE-2026-73283 · OpenSSH sshd (authorized_keys restrict keyword vs tunnel forwarding)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.