---
title: "CVE-2026-54875\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-54875?format=md
keywords: index, follow
---

# CVE-2026-54875

Publication date 29 September 2026

Last updated 30 September 2026

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/CVE-2026-54875?format=md#priority-reason )

Toggle side navigation

## Description

Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-54875?format=md#notes)

### Why is this CVE low priority?

OpenSSL developers have rated this issue as being low severity

[Learn more about Ubuntu priority](https://ubuntu.com/security/cves/about#priority)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssl | 26.04 LTS resolute | Fixed 3.5.5-1ubuntu3.6 |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| openssl-fips | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble  FIPS Updates | Not affected |
| 22.04 LTS jammy  FIPS Updates | Not affected |
| openssl1.0 | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Not affected |
| nodejs | 26.04 LTS resolute | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |
| edk2 | 26.04 LTS resolute | Vulnerable |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| edk2-hwe | 26.04 LTS resolute | Vulnerable |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

edk2 in jammy embeds OpenSSL 1.1.1j
edk2 in noble embeds OpenSSL 3.0.9
edk2 in resolute embeds OpenSSL 3.5.1
edk2 in stonking embeds OpenSSL 3.5.1
nodejs in jammy embeds OpenSSL 1.1.1m
4.0, 3.6, 3.5 and 3.4 are vulnerable

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54875)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-54875)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-54875)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-54875)

### Related Ubuntu Security Notices (USN)

+ [USN-8847-1](https://usn.ubuntu.com/USN-8847-1)
+ OpenSSL vulnerabilities
+ 29 September 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-54875>
