RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability
Published Jan 10, 2026
8.7
HIGHCVSS 4.0
EPSS 0.27%
Description
RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a critical vulnerability exists in the SM2 Public Key Encryption (PKE) implementation where the ephemeral nonce k is generated with severely reduced entropy. A unit mismatch error causes the nonce generation function to request only 32 bits of randomness instead of the expected 256 bits. This reduces the security of the encryption from a 128-bit level to a trivial 16-bit level, allowing a practical attack to recover the nonce k and decrypt any ciphertext given only the public key and ciphertext. This issue has been patched via commit e4f7778.
Affected products
-
Affected
- = 0.14.0-pre.0
- = 0.14.0-rc.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| RustCrypto | Elliptic-Curves | unknown | Affected
|
- 0.14.0
- 0.14.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://crates.io/crates/sm2/0.14.0-pre.0 x_refsource_MISCRelease Notes
- https://crates.io/crates/sm2/0.14.0-rc.0 x_refsource_MISCRelease Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1876 Advisory
- https://github.com/RustCrypto/elliptic-curves/commit/4781762f23ff22ab34763410f648128055c93731 x_refsource_MISCPatch
- https://github.com/RustCrypto/elliptic-curves/commit/e4f77788130d065d760e57fb109370827110a525 x_refsource_MISCPatch
- https://github.com/RustCrypto/elliptic-curves/pull/1600 x_refsource_MISCIssue TrackingPatch
- https://github.com/RustCrypto/elliptic-curves/security/advisories/GHSA-w3g8-fp6j-wvqw x_refsource_CONFIRMExploitMitigationVendor Advisory
- https://github.com/advisories/GHSA-w3g8-fp6j-wvqw Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-22698
| Link | Providers | Tags |
|---|---|---|
| https://crates.io/crates/sm2/0.14.0-pre.0 | x_refsource_MISCRelease Notes | |
| https://crates.io/crates/sm2/0.14.0-rc.0 | x_refsource_MISCRelease Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1876 | Advisory | |
| https://github.com/RustCrypto/elliptic-curves/commit/4781762f23ff22ab34763410f648128055c93731 | x_refsource_MISCPatch | |
| https://github.com/RustCrypto/elliptic-curves/commit/e4f77788130d065d760e57fb109370827110a525 | x_refsource_MISCPatch | |
| https://github.com/RustCrypto/elliptic-curves/pull/1600 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/RustCrypto/elliptic-curves/security/advisories/GHSA-w3g8-fp6j-wvqw | x_refsource_CONFIRMExploitMitigationVendor Advisory | |
| https://github.com/advisories/GHSA-w3g8-fp6j-wvqw | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-22698 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub