{"id":"CVE-2026-22698","summary":"RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability","details":"RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a  critical vulnerability exists in the SM2 Public Key Encryption (PKE) implementation where the ephemeral nonce k is generated with severely reduced entropy. A unit mismatch error causes the nonce generation function to request only 32 bits of randomness instead of the expected 256 bits. This reduces the security of the encryption from a 128-bit level to a trivial 16-bit level, allowing a practical attack to recover the nonce k and decrypt any ciphertext given only the public key and ciphertext. This issue has been patched via commit e4f7778.","aliases":["GHSA-w3g8-fp6j-wvqw"],"modified":"2026-08-12T03:51:13.841162179Z","published":"2026-01-10T05:17:19.993Z","database_specific":{"cwe_ids":["CWE-331"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22698.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://crates.io/crates/sm2/0.14.0-pre.0"},{"type":"WEB","url":"https://crates.io/crates/sm2/0.14.0-rc.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22698.json"},{"type":"ADVISORY","url":"https://github.com/RustCrypto/elliptic-curves/security/advisories/GHSA-w3g8-fp6j-wvqw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22698"},{"type":"FIX","url":"https://github.com/RustCrypto/elliptic-curves/commit/4781762f23ff22ab34763410f648128055c93731"},{"type":"FIX","url":"https://github.com/RustCrypto/elliptic-curves/commit/e4f77788130d065d760e57fb109370827110a525"},{"type":"FIX","url":"https://github.com/RustCrypto/elliptic-curves/pull/1600"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rustcrypto/elliptic-curves","events":[{"introduced":"0faafbd690475c4cc5cce14c9566c920a6d4ea8e"},{"fixed":"4781762f23ff22ab34763410f648128055c93731"},{"fixed":"e4f77788130d065d760e57fb109370827110a525"}],"database_specific":{"cpe":"cpe:2.3:a:rustcrypto:sm2_elliptic_curve:0.14.0:pre0:*:*:*:rust:*:*","extracted_events":[{"introduced":"0.14.0-pre0"},{"last_affected":"0.14.0-pre0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.14.0-pre0","= 0.14.0-pre.0","= 0.14.0-rc.0","x448/v0.14.0-pre.4","sm2/v0.14.0-rc.4","primeorder/v0.14.0-rc.4","primefield/v0.14.0-rc.4","p521/v0.14.0-rc.4","p384/v0.14.0-rc.4","p256/v0.14.0-rc.4","p224/v0.14.0-rc.4","p192/v0.14.0-rc.4","k256/v0.14.0-rc.4","hash2curve/v0.14.0-rc.7","ed448-goldilocks/v0.14.0-pre.7","bp384/v0.14.0-rc.4","bp256/v0.14.0-rc.4","bignp256/v0.14.0-rc.4","x448/v0.14.0-pre.3","sm2/v0.14.0-rc.3","primeorder/v0.14.0-rc.3","primefield/v0.14.0-rc.3","p521/v0.14.0-rc.3","p384/v0.14.0-rc.3","p256/v0.14.0-rc.3","p224/v0.14.0-rc.3","p192/v0.14.0-rc.3","k256/v0.14.0-rc.3","hash2curve/v0.14.0-rc.6","ed448-goldilocks/v0.14.0-pre.6","bp384/v0.14.0-rc.3","bp256/v0.14.0-rc.3","bignp256/v0.14.0-rc.3","x448/v0.14.0-pre.2","sm2/v0.14.0-rc.2","primeorder/v0.14.0-rc.2","primefield/v0.14.0-rc.2","p521/v0.14.0-rc.2","p384/v0.14.0-rc.2","p256/v0.14.0-rc.2","p224/v0.14.0-rc.2","p192/v0.14.0-rc.2","k256/v0.14.0-rc.2","hash2curve/v0.14.0-rc.5","ed448-goldilocks/v0.14.0-pre.5","bp384/v0.14.0-rc.2","bp256/v0.14.0-rc.2","bignp256/v0.14.0-rc.2","sm2/v0.14.0-rc.1","primeorder/v0.14.0-rc.1","primefield/v0.14.0-rc.1","p521/v0.14.0-rc.1","p384/v0.14.0-rc.1","p256/v0.14.0-rc.1","p224/v0.14.0-rc.1","p192/v0.14.0-rc.1","k256/v0.14.0-rc.1","bp384/v0.14.0-rc.1","bp256/v0.14.0-rc.1","bignp256/v0.14.0-rc.1","hash2curve/v0.14.0-rc.4","sm2/v0.14.0-rc.0","bignp256/v0.14.0-rc.0","p521/v0.14.0-rc.0","p384/v0.14.0-rc.0","p256/v0.14.0-rc.0","p224/v0.14.0-rc.0","p192/v0.14.0-rc.0","k256/v0.14.0-rc.0","bp384/v0.14.0-rc.0","bp256/v0.14.0-rc.0","primeorder/v0.14.0-rc.0","hash2curve/v0.14.0-rc.3","primefield/v0.14.0-rc.0","bignp256/v0.14.0-pre.0","x448/v0.14.0-pre.1","sm2/v0.14.0-pre.0","p521/v0.14.0-pre.11","p384/v0.14.0-pre.11","p256/v0.14.0-pre.11","k256/v0.14.0-pre.11","ed448-goldilocks/v0.14.0-pre.4","hash2curve/v0.14.0-rc.2","primeorder/v0.14.0-pre.9","primefield/v0.14.0-pre.6","x448/v0.14.0-pre.0","p521/v0.14.0-pre.10","p384/v0.14.0-pre.10","p256/v0.14.0-pre.10","k256/v0.14.0-pre.10","hash2curve/v0.14.0-rc.1","ed448-goldilocks/v0.14.0-pre.3","bp384/v0.14.0-pre.0","bp256/v0.14.0-pre.0","primeorder/v0.14.0-pre.8","primefield/v0.14.0-pre.5","ed448-goldilocks/v0.14.0-pre.2","primeorder/v0.14.0-pre.7","primefield/v0.14.0-pre.4","p521/v0.14.0-pre.9","p384/v0.14.0-pre.9","p256/v0.14.0-pre.9","k256/v0.14.0-pre.9","hash2curve/v0.14.0-rc.0","p521/v0.14.0-pre.8","p384/v0.14.0-pre.8","p256/v0.14.0-pre.8","k256/v0.14.0-pre.8","primeorder/v0.14.0-pre.6","primefield/v0.14.0-pre.3","p521/v0.14.0-pre.7","p384/v0.14.0-pre.7","p256/v0.14.0-pre.7","k256/v0.14.0-pre.7","primeorder/v0.14.0-pre.5","p521/v0.14.0-pre.6","p384/v0.14.0-pre.6","p256/v0.14.0-pre.6","k256/v0.14.0-pre.6","ed448-goldilocks/v0.14.0-pre.1","ed448-goldilocks/v0.14.0-pre.0","primeorder/v0.14.0-pre.4","p521/v0.14.0-pre.5","p384/v0.14.0-pre.5","p256/v0.14.0-pre.5","k256/v0.14.0-pre.5","primefield/v0.14.0-pre.2","p521/v0.14.0-pre.4","p384/v0.14.0-pre.4","p256/v0.14.0-pre.4","k256/v0.14.0-pre.4","p521/v0.14.0-pre.3","p384/v0.14.0-pre.3","p256/v0.14.0-pre.3","k256/v0.14.0-pre.3","primeorder/v0.14.0-pre.3","primefield/v0.14.0-pre.1","k256/v0.14.0-pre.2","primeorder/v0.14.0-pre.2","p521/v0.14.0-pre.2","p384/v0.14.0-pre.2","p256/v0.14.0-pre.2","k256/v0.14.0-pre.1","primeorder/v0.14.0-pre.1","p521/v0.14.0-pre.1","p384/v0.14.0-pre.1","p256/v0.14.0-pre.1","primefield/v0.14.0-pre.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22698.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}