CVE-2026-18036 PUBLISHED

NTRU leaks private key information by reducing secret values with a non-constant-time integer division

Assigner: bcorg
Reserved: 28.07.2026 Published: 02.10.2026 Updated: 02.10.2026

In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so each reduction was carried out by an integer division whose latency depends on the secret operand. Polynomial.modQ divided by a variable divisor, which a compiler cannot strength-reduce to a multiply the way it can a constant one, so it emitted a division on every call including on the decapsulation path where the dividend derives from the private key; Polynomial.mod3 and NTRUSampling.mod3 divided the secret key polynomials f and g during key generation, the message polynomials r and m during encapsulation, and coefficients recovered during decapsulation. An attacker able to measure that timing can recover information about the NTRU private key. modQ now masks, which is exact because q is always a power of two, and mod3 uses the reference implementation's division-free fold and select; the results are unchanged.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Amber
CVSS Score: 8.2

Product Status

Vendor Legion of the Bouncy Castle Inc.
Product BC-JAVA
Versions Default: unaffected
  • affected from 1.73 to 1.86 (excl.)

Credits

  • The Robusta team: Deepak Bhargavan Pillai, Anirban Chakraborty, Chitchanok Chuengsatiansup, Matthew Roughan, Peter Schwabe, and Yuval Yarom reporter

References

Problem Types

  • CWE-208 Observable Timing Discrepancy CWE