CVE-2026-77696
EUVD-2026-8901229.09.2026, 16:17
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openssl | openssl | 4.0.0 ≤ 𝑥 < 4.0.3 | CNA |
| openssl | openssl | 3.6.0 ≤ 𝑥 < 3.6.5 | CNA |
| openssl | openssl | 3.5.0 ≤ 𝑥 < 3.5.9 | CNA |
| openssl | openssl | 3.4.0 ≤ 𝑥 < 3.4.8 | CNA |
| openssl | openssl | 3.0.0 ≤ 𝑥 < 3.0.23 | CNA |
Debian Releases
References