GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSL: non-constant-time SM2 point multiplication on AArch64 and RISC-V leaks key bits via timing and cache

CVSS 3.7CVE-2026-54875Kernel, userspace & hypervisorcurated

Impact

The optimized SM2 scalar multiplication used on ARM64 and RISC-V branches and indexes tables according to secret bits, so execution time and cache-line access depend on the long-term private key during SM2 decryption and on the per-signature nonce during signing. An attacker co-resident on the same physical host - a neighbouring tenant on an Arm-based head node or Grace-class GPU server - who can time or observe cache behaviour of those operations can recover information about the secret scalar. Practical only where SM2 is actually in use, which for most operators is nowhere; TLS with ECDSA/RSA and the FIPS module are unaffected. Treat this as relevant if you run SM2 certificates or a Chinese-market cryptographic profile on Arm or RISC-V hardware.

Who can reach it

An attacker able to measure timing of, or observe cache-line access patterns for, SM2 signing or decryption on an affected AArch64 or RISC-V host - in practice local or co-resident on the machine performing the SM2 operation. No credentials on the target service are stated as required.

What to do

Upgrade OpenSSL: 4.0 users to 4.0.3, 3.6 to 3.6.5, 3.5 to 3.5.9, 3.4 to 3.4.8. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected. Distro packages are the usual path; every daemon linked against the shared library has to be restarted (or the node rebooted) before the new code is in use - no firmware or node drain needed. Statically linked appliances and containers need rebuilt images.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.