CVE-2026-77696
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Summary
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.
Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.
CWE: CWE-208: Observable Timing Discrepancy
Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.
Applications performing SM2 signature generation are affected on all platforms.
FIPS Impact: no SM2 is not a FIPS algorithm.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenSSL | OpenSSL | 4.0.0 < 4.0.3 | affected |
| OpenSSL | OpenSSL | 3.6.0 < 3.6.5 | affected |
| OpenSSL | OpenSSL | 3.5.0 < 3.5.9 | affected |
| OpenSSL | OpenSSL | 3.4.0 < 3.4.8 | affected |
| OpenSSL | OpenSSL | 3.0.0 < 3.0.23 | affected |
| OpenSSL | OpenSSL | 1.1.1 < 1.1.1zj | affected |
Weaknesses
- CWE-208: CWE-208 Observable Timing Discrepancy
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://openssl-library.org/news/secadv/20260929.txt
- https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb
- https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9
- https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440
- https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.