CVE-2026-77696
Received Received - Intake

SM2 Signature Generation Timing Side-Channel in OpenSSL

Vulnerability report for CVE-2026-77696, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves SM2 signature generation using non-constant-time arithmetic on secret values, creating a timing side-channel. Attackers measuring signing times can infer information about the secret nonce used per signature. Over many signatures, this may allow private key recovery via lattice or Hidden Number Problem attacks.

Detection Guidance

This vulnerability involves a timing side-channel in SM2 signature generation. Detection requires analyzing timing variations during signature operations. No specific commands are provided in the context to detect this issue directly.

Impact Analysis

If you use systems performing SM2 signatures, an attacker could exploit timing differences to recover your private key over time. This could lead to unauthorized access, forged signatures, or data breaches depending on how SM2 is used in your environment.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it relates to timing side-channel attacks on cryptographic operations rather than data protection failures. However, if exploited, it could lead to private key compromise, which may indirectly impact compliance by exposing sensitive data protected under these regulations.

Mitigation Strategies

Immediate mitigation involves updating OpenSSL to a patched version that uses constant-time operations for SM2 signatures. Avoid using SM2 signatures until the update is applied. Monitor OpenSSL security advisories for fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77696. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart