CVE-2026-77696: Timing Side-Channel in SM2 Signature Generation
Published Sep 29, 2026
·Updated
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.
Other sources
Timing Side-Channel in SM2 Signature Generation
— Debian
Affected Software
2 affected components
OpenSSL OpenSSL
debian/openssl<=3.0.20-1~deb12u2, <=3.0.22-1~deb12u1, <=3.5.7-1~deb13u2, <=3.6.4-1
Event History
Sep 29, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via Ubuntu·07:45 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:46 PM
Description
Data Sourced
via Debian·07:46 PM
DescriptionAffected Software
Frequently Asked Questions
1
Who is exposed to this timing side channel?
Applications that perform SM2 signature generation are affected on all platforms. The issue applies to SM2 signing operations because variable-time BIGNUM arithmetic processes the secret nonce and private key.
2
What does an attacker need to exploit the issue?
An attacker needs to be able to measure SM2 signing times across many signatures. Those measurements may reveal information about per-signature secret nonces that can be used in a lattice or Hidden Number Problem attack to recover the private key.
3
Does this affect FIPS-approved cryptographic operations?
No. SM2 is not a FIPS algorithm, so the advisory states there is no FIPS impact.