{"id":"CVE-2026-77696","summary":"Timing Side-Channel in SM2 Signature Generation","details":"Issue summary: SM2 signature generation uses non-constant-time arithmetic\non secret values, forming a timing side-channel.\n\nImpact summary: An attacker able to measure SM2 signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: SM2 signature generation computes the signature value using\nvariable-time BIGNUM operations on the secret nonce and the private key, so\nthe time taken to produce an SM2 signature depends on these secret values,\nforming a timing side-channel.\n\nApplications performing SM2 signature generation are affected on all\nplatforms.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm.","modified":"2026-09-30T08:16:02.800644374Z","published":"2026-09-29T15:32:22.520Z","database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-208"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77696.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.23"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77696.json"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77696"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260929.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"fixed":"af1775b60dfa141a4ad762585052cabeb9f37e9e"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"c8bd5a57108599ac650bbae77fcabe3109dab2e8"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"45e844fa2a14ec92d146bd8f5778ac130b6625fb"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"e72c946f6f6d94c8ba5119acb25340b7b6b2073f"},{"introduced":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"e04bd3433fd84e1861bf258ea37928d9845e6a86"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.3"},{"introduced":"3.6.0"},{"fixed":"3.6.5"},{"introduced":"3.5.0"},{"fixed":"3.5.9"},{"introduced":"3.4.0"},{"fixed":"3.4.8"},{"introduced":"1.1.1"},{"fixed":"1.1.1zj"}],"source":"AFFECTED_FIELD"}}],"versions":["openssl-3.4.7","openssl-3.5.8","openssl-3.6.4","openssl-4.0.2","openssl-3.4.6","openssl-3.5.7","openssl-3.6.3","openssl-4.0.1","openssl-4.0.0","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.4.1","openssl-3.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-77696.json","vanir_signatures":[{"id":"CVE-2026-77696-c377fa22","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e04bd3433fd84e1861bf258ea37928d9845e6a86","target":{"file":"include/openssl/opensslv.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["28170854778703993674264004058177114599","73132526844288570625317440636111911761","177405411499435185068645597737938634778","224809958623850711330610094965797758930","295554444428855106393106961197201359586"]}}],"vanir_signatures_modified":"2026-09-30T08:16:02Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}