Looking for the vulnerability index of Invicti's legacy products?
OpenSSL Observable Timing Discrepancy Vulnerability (CVE-2026-54875) - Vulnerability Database

OpenSSL Observable Timing Discrepancy Vulnerability (CVE-2026-54875)

Description

Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar m

References

Related Vulnerabilities