Issue summary: SM2 signature generation uses non-constant-time arithmetic
on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn
information about the per-signature secret nonce, which over many signatures
can, via a lattice / Hidden Number Problem attack, lead to recovery of the
private key. CWE: CWE-208: Observable Timing Discrepancy
Description: SM2 signature generation computes the signature value using
variable-time BIGNUM operations on the secret nonce and the private key, so
the time taken to produce an SM2 signature depends on these secret values,
forming a timing side-channel.
Applications performing SM2 signature generation are affected on all
platforms.
FIPS Impact: no
SM2 is not a FIPS algorithm.
Характеристики атаки
Последствия
Строка CVSS v3.1
Тип уязвимости (CWE)
Уязвимые продукты 6
| Конфигурация | От (включительно) | До (исключительно) |
|---|---|---|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
1.1.1
|
1.1.1zj
|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
3.0.0
|
3.0.23
|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
3.4.0
|
3.4.8
|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
3.5.0
|
3.5.9
|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
3.6.0
|
3.6.5
|
|
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
|
4.0.0
|
4.0.3
|