CVE-2026-18036 Bouncy Castle NTRU 时序侧信道信息泄露漏洞
影响攻击者可通过计时分析恢复 NTRU 私钥信息
Bouncy Castle for Java 1.86 之前版本的 NTRU 实现中,三个辅助函数使用 % 运算符对秘密值进行约简,导致每次调用都会执行整数除法,而除法延迟依赖于秘密操作数。攻击者若能测量该时序差异,即可获取 NTRU 私钥相关信息。
影响范围
Bouncy Castle for Java 1.86 之前的版本,具体受影响版本范围暂无公开信息。
漏洞详情
漏洞属于时序侧信道类型。Polynomial.modQ 使用变量除数进行除法,编译器无法像常量除数那样将其强度削减为乘法,因此在每次调用(包括解密路径)时都会产生依赖秘密数据的除法运算;Polynomial.mod3 和 NTRUSampling.mod3 在密钥生成、封装和解封装过程中对秘密多项式进行除法。攻击者通过测量这些操作的执行时间差异,可推断私钥信息。
利用条件与风险
利用前提是攻击者能够对目标系统进行高精度计时测量,实战中在共享环境或可观测延迟的场景下存在风险,但利用难度较高。
修复建议
升级至 Bouncy Castle for Java 1.86 或更高版本,该版本中 modQ 改为掩码操作(因 q 恒为 2 的幂,结果精确),mod3 改用无除法的折叠与选择实现,结果不变。临时缓解措施暂无公开信息。
In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor, which a compiler cannot strength-reduce to a multiply the way it can a constant one, so it emitted a division on every call including on the decapsulation path where the dividend derives from the private key; Polynomial.mod3 and NTRUSampling.mod3 divided the secret key polynomials f and g during key generation, the message polynomials r and m during encapsulation, and coefficients recovered during decapsulation. An attacker able to measure that timing can recover information about the NTRU private key. modQ now masks, which is exact because q is always a power of two, and mod3 uses the reference implementation’s division-free fold and select; the results are unchanged.