CVE-2026-18036
W Bouncy Castle dla Javy przed 1.86 atakujący może odzyskać informacje o kluczu prywatnym przez analizę czasu operacji.
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor, which a compiler cannot strength-reduce to a multiply the way it can a constant one, so it emitted a division on every call including on the decapsulation path where the dividend derives from the private key; Polynomial.mod3 and NTRUSampling.mod3 divided the secret key polynomials f and g during key generation, the message polynomials r and m during encapsulation, and coefficients recovered during decapsulation. An attacker able to measure that timing can recover information about the NTRU private key. modQ now masks, which is exact because q is always a power of two, and mod3 uses the reference implementation's division-free fold and select; the results are unchanged.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-10-02 08:17:01 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:17:03 UTC |
- https://github.com/bcgit/bc-java/commit/9c9ad88b6003bb6230d2434bd892cc1e95b294e4 (91579145-5d7b-4cc5-b925-a0262ff19630)
- https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9018036 (91579145-5d7b-4cc5-b925-a0262ff19630)