In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag… (CVE-2026-64313)
A vulnerability in the Linux kernel's crypto ECC implementation was fixed to address an incorrect carry flag calculation during very large integer (vli) multiplication. The issue occurred when the high part of an intermediate result was saturated and an overflow from lower bits was not properly accounted for, potentially leading to incorrect cryptographic computations. This was introduced when the ECC code was refactored and a critical boundary check was lost. The fix restores proper handling of carry from lower-bit overflow in the multiplication operation.
AI Analysis
Technical Summary
CVE-2026-64313 addresses a vulnerability in the Linux kernel's elliptic curve cryptography (ECC) code, specifically in the vli multiplication implementation. The carry flag calculation failed when the high part of an intermediate multiplication result (r01.m_high) was saturated at 0xFFFFFFFFFFFFFFFF and an overflow occurred in the addition of lower bits. The original condition did not handle cases where r01.m_high equaled the product's high part but an additional carry existed from the lower bits. This flaw was introduced during a refactor that split the muladd() function into separate multiplication and addition helpers, losing a critical check. The patch adds proper handling for this boundary condition by accounting for the carry from the lower addition, ensuring correct cryptographic computations.
Potential Impact
The vulnerability could cause incorrect calculations in the ECC cryptographic operations within the Linux kernel. While no specific exploitation or impact scenarios are detailed, incorrect cryptographic computations could undermine the security guarantees of ECC-based operations relying on this code. There are no known exploits in the wild reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a kernel cryptographic code fix, users should monitor official Linux kernel releases and apply updates once the fix is included. No alternative mitigations are provided.
In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag… (CVE-2026-64313)
Description
A vulnerability in the Linux kernel's crypto ECC implementation was fixed to address an incorrect carry flag calculation during very large integer (vli) multiplication. The issue occurred when the high part of an intermediate result was saturated and an overflow from lower bits was not properly accounted for, potentially leading to incorrect cryptographic computations. This was introduced when the ECC code was refactored and a critical boundary check was lost. The fix restores proper handling of carry from lower-bit overflow in the multiplication operation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-64313 addresses a vulnerability in the Linux kernel's elliptic curve cryptography (ECC) code, specifically in the vli multiplication implementation. The carry flag calculation failed when the high part of an intermediate multiplication result (r01.m_high) was saturated at 0xFFFFFFFFFFFFFFFF and an overflow occurred in the addition of lower bits. The original condition did not handle cases where r01.m_high equaled the product's high part but an additional carry existed from the lower bits. This flaw was introduced during a refactor that split the muladd() function into separate multiplication and addition helpers, losing a critical check. The patch adds proper handling for this boundary condition by accounting for the carry from the lower addition, ensuring correct cryptographic computations.
Potential Impact
The vulnerability could cause incorrect calculations in the ECC cryptographic operations within the Linux kernel. While no specific exploitation or impact scenarios are detailed, incorrect cryptographic computations could undermine the security guarantees of ECC-based operations relying on this code. There are no known exploits in the wild reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this is a kernel cryptographic code fix, users should monitor official Linux kernel releases and apply updates once the fix is included. No alternative mitigations are provided.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-x49g-5fpg-2qxf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64313"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420d9c2644c7f808568e
Added to database: 07/25/2026, 23:09:01 UTC
Last enriched: 07/25/2026, 23:34:05 UTC
Last updated: 07/26/2026, 03:43:59 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.