CVE-2025-9231 is a timing side-channel vulnerability in the SM2 algorithm implementation on 64-bit ARM platforms, potentially allowing remote recovery of private keys. While OpenSSL does not directly support SM2 keys in TLS, custom providers could enable this, making the vulnerability relevant in such contexts. It is rated Medium severity with a CVSS score of 6.5, indicating a network attack vector with low complexity that could lead to partial confidentiality loss. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.0, < 3.2.6CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.5CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.3CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.4CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026openssl: Timing side-channel in SM2 algorithm on 64 bit ARM
Sep 30, 2025Timing side-channel in SM2 algorithm on 64 bit ARM
Sep 30, 2025Timing side-channel in SM2 algorithm on 64 bit ARM
Sep 9, 2025