Timing Side-Channel Vulnerability in SM2 Signature Generation for OpenSSL
CVE-2026-77696
Currently unrated
What is CVE-2026-77696?
The SM2 signature generation in OpenSSL employs non-constant-time arithmetic operations on confidential values, which can lead to timing discrepancies. An attacker monitoring the time taken for signature generation could potentially extract sensitive information about the nonce used for each signature. This can result in the ability to recover the private key over a series of signatures through sophisticated attacks such as the Lattice or Hidden Number Problem techniques. Applications utilizing SM2 signature generation across all platforms are susceptible to this vulnerability, posing an ongoing threat to the integrity of cryptographic operations.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9