Executive brief
OpenSSL is a widely used security library that provides encryption and secure communication for websites and applications. A vulnerability in its implementation of the SM2 digital signature algorithm on 64-bit ARM systems could allow an attacker to potentially recover a server's private encryption key by measuring the time it takes to perform cryptographic operations. If successful, this would allow the attacker to impersonate the service or decrypt sensitive communications.
Technical details
A timing side-channel vulnerability (CWE-385) exists in the SM2 signature computation implementation within OpenSSL when running on 64-bit ARM (aarch64) platforms. The root cause is the use of non-constant-time modular inversion in the ecp_sm2p256.c component. While OpenSSL does not natively support SM2 in standard TLS contexts, applications using custom providers or specific SM2 implementations are at risk. An attacker could potentially recover the private key by performing precise remote timing measurements of signature operations. The issue is addressed by implementing constant-time modular inversion.
Affected products
- OpenSSL Foundation OpenSSL 3.2.0 - 3.2.5, 3.3.0 - 3.3.4, 3.4.0 - 3.4.2, 3.5.0 - 3.5.3
Timeline
- 2025-08-18: other: Reported to OpenSSL by Stanislav Fort
- 2025-09-30: advisory: OpenSSL Security Advisory published
- 2025-09-30: patched: Fixed in OpenSSL 3.5.4, 3.4.3, 3.3.5, and 3.2.6
References
- https://github.com/openssl/openssl/commit/567f64386e43683888212226824b6a179885a0fe
- https://github.com/openssl/openssl/commit/cba616c26ac8e7b37de5e77762e505ba5ca51698
- https://github.com/openssl/openssl/commit/eed5adc9f969d77c94f213767acbb41ff923b6f4
- https://github.com/openssl/openssl/commit/fc47a2ec078912b3e914fab5734535e76c4820c2
- https://openssl-library.org/news/secadv/20250930.txt
- http://www.openwall.com/lists/oss-security/2025/09/30/5
- http://www.openwall.com/lists/oss-security/2026/05/11/11