GHSA-9qr7-mmm2-9f2rLowCVSS 3.7

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values,...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.

Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.

CWE: CWE-208: Observable Timing Discrepancy

Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.

Applications performing SM2 signature generation are affected on all platforms.

FIPS Impact: no SM2 is not a FIPS algorithm.

🔗 References (7)