CVE-2026-77696

Summary

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.

Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.

CWE: CWE-208: Observable Timing Discrepancy

Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.

Applications performing SM2 signature generation are affected on all platforms.

FIPS Impact: no SM2 is not a FIPS algorithm.

Affected Software

VendorProductVersion RangeStatus
OpenSSLOpenSSL4.0.0 < 4.0.3affected
OpenSSLOpenSSL3.6.0 < 3.6.5affected
OpenSSLOpenSSL3.5.0 < 3.5.9affected
OpenSSLOpenSSL3.4.0 < 3.4.8affected
OpenSSLOpenSSL3.0.0 < 3.0.23affected
OpenSSLOpenSSL1.1.1 < 1.1.1zjaffected

Weaknesses

  • CWE-208: CWE-208 Observable Timing Discrepancy

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References