{"id":"CVE-2026-77696","summary":"Timing Side-Channel in SM2 Signature Generation","details":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm.","modified":"2026-09-30T08:06:06.268475Z","published":"2026-09-29T15:32:22.520Z","database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-208"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77696.json","unresolved_ranges":[{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.3"},{"introduced":"3.6.0"},{"fixed":"3.6.5"},{"introduced":"3.5.0"},{"fixed":"3.5.9"},{"introduced":"3.4.0"},{"fixed":"3.4.8"},{"introduced":"3.0.0"},{"fixed":"3.0.23"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77696.json"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260929.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"e04bd3433fd84e1861bf258ea37928d9845e6a86"}],"database_specific":{"extracted_events":[{"introduced":"1.1.1"},{"fixed":"1.1.1zj"}],"source":"AFFECTED_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77696.json","vanir_signatures_modified":"2026-09-30T08:06:06Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e04bd3433fd84e1861bf258ea37928d9845e6a86","target":{"file":"include/openssl/opensslv.h"},"deprecated":false,"digest":{"line_hashes":["28170854778703993674264004058177114599","73132526844288570625317440636111911761","177405411499435185068645597737938634778","224809958623850711330610094965797758930","295554444428855106393106961197201359586"],"threshold":0.9},"id":"CVE-2026-77696-c377fa22"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}