Sceawere
Vulnerability Detail
CVE-2026-77696UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SM2 Timing Side-Channel Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 9h ago
- Vendor
- OpenSSL
- Product
- OpenSSL
- Attack Type
- CWE-208 Observable Timing Discrepancy
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-09-29T16:17:11.493Z",
"pubdate": "2026-09-29T16:17:11.493Z",
"executiveSummary": "The SM2 signature generation process is susceptible to a timing side-channel vulnerability categorized under CWE-208: Observable Timing Discrepancy. The vulnerability stems from the use of non-constant-time BIGNUM arithmetic during the processing of secret nonce values and private keys.\nBy measuring the precise time taken to perform signature generation, a remote or local attacker can extract statistical information regarding the per-signature secret nonce. Over a sufficient number of signature operations, this leakage allows an attacker to mount a lattice-based attack, specifically leveraging the Hidden Number Problem (HNP) to reconstruct the victim's private signing key.\nThis issue affects any application performing SM2 signature generation across all hardware and software platforms. While the vulnerability is platform-agnostic, exploitation requires the attacker to have high-resolution timing measurement capabilities and the ability to trigger a significant volume of signing operations. This represents a critical cryptographic implementation flaw that undermines the confidentiality of the private key material, potentially leading to full compromise of the cryptographic identity.",
"technicalDetails": "The root cause of the vulnerability lies in the implementation of the SM2 digital signature algorithm, which fails to ensure constant-time execution for modular arithmetic operations involving secret material. Specifically, the BIGNUM library utilized for SM2 signing performs conditional branching or variable-latency operations dependent on the bit-pattern of the secret nonce (k) and the private key (d).\nIn SM2 signing, the generation of the signature involves the scalar multiplication of the base point and modular arithmetic operations. Because the BIGNUM implementation is not constant-time, the CPU instruction execution path—and consequently the overall execution latency—correlates directly with the Hamming weight or specific bit values of the secret inputs. This creates a measurable timing discrepancy between different signing operations.\nThe exploitation flow follows these phases: first, an attacker must observe multiple signature operations from the target system. The attacker uses high-precision timers (e.g., via network latency analysis or local CPU cycle counters) to correlate specific temporal signatures with the generated digital signatures. Second, the collected timing measurements are transformed into a set of linear inequalities regarding the unknown nonce values. Third, the attacker applies lattice-based cryptanalysis, such as the LLL (Lenstra–Lenstra–Lovász) algorithm or BKZ reduction, to solve the Hidden Number Problem (HNP).\nThe HNP attack allows for the recovery of the private key once enough bits of the nonces are leaked through the side-channel. Since SM2 signature schemes are sensitive to even minor leakage of the nonce, the reconstruction of the private key becomes feasible once a sufficient number of signatures (typically several hundred to thousands, depending on noise levels) have been harvested. The vulnerability is persistent across all implementations that lack constant-time BIGNUM primitives. No authentication or specific privileges are required to exploit the timing channel, as the vulnerability is inherent to the signing function itself. The impact is catastrophic, as it results in the total loss of the private key's confidentiality, allowing an attacker to forge valid signatures indefinitely for the compromised entity."
}