CVE-2026-77696

EUVD-2026-89012
Issue summary: SM2 signature generation uses non-constant-time arithmetic
on secret values, forming a timing side-channel.

Impact summary: An attacker able to measure SM2 signing times may learn
information about the per-signature secret nonce, which over many signatures
can, via a lattice / Hidden Number Problem attack, lead to recovery of the
private key.

CWE: CWE-208: Observable Timing Discrepancy

Description: SM2 signature generation computes the signature value using
variable-time BIGNUM operations on the secret nonce and the private key, so
the time taken to produce an SM2 signature depends on these secret values,
forming a timing side-channel.

Applications performing SM2 signature generation are affected on all
platforms.

FIPS Impact: no
SM2 is not a FIPS algorithm.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
opensslCNA
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
opensslopenssl
4.0.0 ≤
𝑥
< 4.0.3
CNA
opensslopenssl
3.6.0 ≤
𝑥
< 3.6.5
CNA
opensslopenssl
3.5.0 ≤
𝑥
< 3.5.9
CNA
opensslopenssl
3.4.0 ≤
𝑥
< 3.4.8
CNA
opensslopenssl
3.0.0 ≤
𝑥
< 3.0.23
CNA
Debian logo
Debian Releases
Debian Product
Codename
openssl
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
vulnerable