Bug 2544959 (CVE-2026-18036) - CVE-2026-18036 bouncycastle: bouncycastle: Information disclosure via timing side-channel in NTRU
Summary: CVE-2026-18036 bouncycastle: bouncycastle: Information disclosure via timing ...
Keywords:
Status: NEW
Alias: CVE-2026-18036
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2545143 2545144
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-02 08:01 UTC by OSIDB Bzimport
Modified: 2026-10-02 12:26 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-02 08:01:12 UTC
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor, which a compiler cannot strength-reduce to a multiply the way it can a constant one, so it emitted a division on every call including on the decapsulation path where the dividend derives from the private key; Polynomial.mod3 and NTRUSampling.mod3 divided the secret key polynomials f and g during key generation, the message polynomials r and m during encapsulation, and coefficients recovered during decapsulation. An attacker able to measure that timing can recover information about the NTRU private key. modQ now masks, which is exact because q is always a power of two, and mod3 uses the reference implementation's division-free fold and select; the results are unchanged.


Note You need to log in before you can comment on or make changes to this bug.