Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.
Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.
CWE: CWE-208: Observable Timing Discrepancy
Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.
Applications performing SM2 signature generation are affected on all platforms.
FIPS Impact: no SM2 is not a FIPS algorithm.
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | openssl-main-3.5.9-0.1.hum1 | * |
| Red Hat Hardened Images | RedHat | openssl3-main-3.5.9-0.1.hum1 | * |
| Nodejs | Ubuntu | esm-apps/jammy | * |
| Nodejs | Ubuntu | jammy | * |
| Openssl | Ubuntu | esm-infra-legacy/trusty | * |
| Openssl | Ubuntu | esm-infra-legacy/xenial | * |
| Openssl | Ubuntu | esm-infra/bionic | * |
| Openssl | Ubuntu | esm-infra/focal | * |
| Openssl | Ubuntu | jammy | * |
| Openssl | Ubuntu | noble | * |
| Openssl | Ubuntu | resolute | * |
| Openssl | Ubuntu | upstream | * |
| Openssl1.0 | Ubuntu | esm-infra/bionic | * |