Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
Published Sep 29, 2026
5.9
MEDIUMCVSS 3.1
EPSS 0.26%
Description
Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.
Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.
CWE: CWE-208: Observable Timing Discrepancy
Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.
The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.
Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.
The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.
FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path.
Affected products
-
- Version 1.0.2StatusaffectedConstraints<1.0.2zs
- Version 1.1.1StatusaffectedConstraints<1.1.1zj
- Version 3.0.0StatusaffectedConstraints<3.0.23
- Version 3.4.0StatusaffectedConstraints<3.4.8
- Version 3.5.0StatusaffectedConstraints<3.5.9
- Version 3.6.0StatusaffectedConstraints<3.6.5
- Version 4.0.0StatusaffectedConstraints<4.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Hardened Images
openssl-main-3.5.9-0.1.hum1
Fixed · RHSA-2026:74162
Red Hat Hardened Images
openssl3-main-3.5.9-0.1.hum1
Fixed · RHSA-2026:74166
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Fix deferred
Red Hat Enterprise Linux 10
edk2
Fix deferred
Red Hat Enterprise Linux 10
openssl
Affected
Red Hat Enterprise Linux 10
shim
Fix deferred
Red Hat Enterprise Linux 10
shim-unsigned-aarch64
Fix deferred
Red Hat Enterprise Linux 10
shim-unsigned-x64
Fix deferred
Red Hat Enterprise Linux 6
openssl
Out of support scope
Red Hat Enterprise Linux 7
openssl
Fix deferred
Red Hat Enterprise Linux 7
ovmf
Fix deferred
Red Hat Enterprise Linux 7
shim-signed
Fix deferred
Red Hat Enterprise Linux 8
compat-openssl10
Fix deferred
Red Hat Enterprise Linux 8
edk2
Fix deferred
Red Hat Enterprise Linux 8
mingw-openssl
Fix deferred
Red Hat Enterprise Linux 8
openssl
Fix deferred
Red Hat Enterprise Linux 8
shim
Fix deferred
Red Hat Enterprise Linux 8
shim-unsigned-aarch64
Fix deferred
Red Hat Enterprise Linux 8
shim-unsigned-x64
Fix deferred
Red Hat Enterprise Linux 9
compat-openssl11
Fix deferred
Red Hat Enterprise Linux 9
edk2
Fix deferred
Red Hat Enterprise Linux 9
openssl
Affected
Red Hat Enterprise Linux 9
shim
Fix deferred
Red Hat Enterprise Linux 9
shim-unsigned-aarch64
Fix deferred
Red Hat Enterprise Linux 9
shim-unsigned-x64
Fix deferred
Red Hat Hardened Images
unbound
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
Red Hat Satellite 6
openvox-agent
Fix deferred
Red Hat Satellite 6
puppet-agent
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | openssl-main-3.5.9-0.1.hum1 | Fixed | RHSA-2026:74162 |
| Red Hat Hardened Images | openssl3-main-3.5.9-0.1.hum1 | Fixed | RHSA-2026:74166 |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | openssl | Affected | n/a |
| Red Hat Enterprise Linux 10 | shim | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-aarch64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-x64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | shim-signed | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | shim | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | shim-unsigned-aarch64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | shim-unsigned-x64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | openssl | Affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-aarch64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-x64 | Fix deferred | n/a |
| Red Hat Hardened Images | unbound | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
| Red Hat Satellite 6 | openvox-agent | Fix deferred | n/a |
| Red Hat Satellite 6 | puppet-agent | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-54872 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543250 Issue Tracking
- https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179 patch
- https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb patch
- https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd patch
- https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471 patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-54872
- https://openssl-library.org/news/secadv/20260929.txt vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-54872
Change history (0)
No recorded changes yet.