CVE-2026-18036

⚪ Do wiadomości

W Bouncy Castle dla Javy przed 1.86 atakujący może odzyskać informacje o kluczu prywatnym przez analizę czasu operacji.

CVSS
0.0
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor, which a compiler cannot strength-reduce to a multiply the way it can a constant one, so it emitted a division on every call including on the decapsulation path where the dividend derives from the private key; Polynomial.mod3 and NTRUSampling.mod3 divided the secret key polynomials f and g during key generation, the message polynomials r and m during encapsulation, and coefficients recovered during decapsulation. An attacker able to measure that timing can recover information about the NTRU private key. modQ now masks, which is exact because q is always a power of two, and mod3 uses the reference implementation's division-free fold and select; the results are unchanged.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-10-02 08:17:01 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:17:03 UTC
Referencje