{"id":"AZL-105519","summary":"CVE-2026-77696 affecting package kata-containers 4.1.0.kata0-1","details":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm.","modified":"2026-10-03T14:16:34.148996657Z","published":"2026-09-29T16:17:11Z","upstream":["CVE-2026-77696"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696"}],"affected":[{"package":{"name":"kata-containers","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kata-containers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.1.0.kata0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105519.json"}}],"schema_version":"1.9.0"}