CVE-2026-64313 Details
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.
A vulnerability in the Linux kernel's handling of elliptic curve cryptography (ECC) can lead to incorrect calculations in variable-length integer (VLI) multiplication. This issue arises because the carry flag is not properly calculated when the high part of a number is at its maximum and the lower bits overflow. The problem was introduced when ECC software support was added, which separated a multiplication and addition function into two distinct helpers. The new functions lost the necessary check for this specific overflow scenario. As a result, the vulnerability could potentially be exploited to manipulate cryptographic operations that rely on accurate ECC calculations.
Users can upgrade to the patched version of the Linux kernel available in the official Linux repositories.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/24a54dfa06d09813b4802a374fad3d2c0e16a884 | kernel.org | Patch |
| https://git.kernel.org/stable/c/27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5275e0fca256d081e2e7d4ba3dd8216c6e50d44e | kernel.org | Patch |
| https://git.kernel.org/stable/c/677450e5ef850c4d28b7956aa01104548c2a894e | kernel.org | Patch |
| https://git.kernel.org/stable/c/774ddddf5eb26eeca177350413e3e2bc50930ee9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b709e0e768766abe29a49e1c1922a1604be602f4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d11b2bb99bec1f5557c01cac42231e23745f49b8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ebaae7c4251cc0cdb2602f334d4f08a3e82d271e | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.8, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |