CVE-2026-54872
Publication date 29 September 2026
Last updated 30 September 2026
Ubuntu priority
Description
Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
Read the notes from the security team
Why is this CVE low priority?
OpenSSL developers have rated this issue as being low severity
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openssl | 26.04 LTS resolute |
Fixed 3.5.5-1ubuntu3.6
|
| 24.04 LTS noble |
Fixed 3.0.13-0ubuntu3.16
|
|
| 22.04 LTS jammy |
Fixed 3.0.2-0ubuntu1.30
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| openssl-fips | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| openssl1.0 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 18.04 LTS bionic |
Needs evaluation
|
|
| nodejs | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Not affected
|
|
| edk2 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| edk2-hwe | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release |
Notes
mdeslaur
edk2 in jammy embeds OpenSSL 1.1.1j edk2 in noble embeds OpenSSL 3.0.9 edk2 in resolute embeds OpenSSL 3.5.1 edk2 in stonking embeds OpenSSL 3.5.1 nodejs in jammy embeds OpenSSL 1.1.1m 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable
References
Related Ubuntu Security Notices (USN)
- USN-8847-1
- OpenSSL vulnerabilities
- 29 September 2026