Information Exposure Through Timing Discrepancy in OpenSSL - CVE-2026-77696
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to recover a private key.
The vulnerability exists due to an observable timing discrepancy in SM2 signature generation when performing arithmetic on secret nonce and private-key values. A remote attacker can measure signing times across many signatures to recover a private key.
The issue affects SM2 signature generation on all platforms.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-77696
openssl (Debian package) - update to 3.5.7-1~deb13u3