Ad

CVE-2026-77696

LOW CVSS 3.1: 3,7 EPSS 0.24%
Обновлено 8 октября 2026
OpenSSL
Параметр Значение
CVSS 3,7 (LOW)
Уязвимые версии 1.1.1 — 4.0.3
Устранено в версии 1.1.1zj
Тип уязвимости CWE-208
Поставщик OpenSSL
Публичный эксплойт Нет

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.

Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Высокая
Сложно эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Низкое
Частичная утечка данных
Целостность
Нет
Нет модификации данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1

Тип уязвимости (CWE)

Уязвимые продукты 6

Конфигурация От (включительно) До (исключительно)
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
1.1.1 1.1.1zj
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.0.0 3.0.23
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.4.0 3.4.8
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.5.0 3.5.9
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
3.6.0 3.6.5
Openssl Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
4.0.0 4.0.3