Timing Attack Affecting openssl package, versions [3.4.0,3.4.8)[3.5.0,3.5.9)[3.6.0,3.6.5)[4.0.1,4.0.3)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-OPENSSL-20537038
  • published6 Oct 2026
  • disclosed29 Sept 2026
  • creditAbhinav Agarwal,Feng Xue

Introduced: 29 Sep 2026

NewCVE-2026-54875  (opens in a new tab)
CWE-208  (opens in a new tab)

How to fix?

Upgrade openssl to version 3.4.8, 3.5.9, 3.6.5, 4.0.3 or higher.

Overview

Affected versions of this package are vulnerable to Timing Attack in the ARM64 and RISC-V optimized SM2 scalar multiplication, which selects conditional branches and table lookups by secret scalar bits. An attacker can learn the long term private key or a per signature nonce by measuring execution time or observing cache access patterns. This is confined to SM2 on those two architectures, and cache observation requires the attacker to run code on the same host.

CVSS Base Scores

version 4.0
version 3.1