Answer in brief
CVE-2026-64313 records a Unknown severity vulnerability in crypto: ecc - Fix carry overflow in vli multiplication. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64313 records a Unknown severity vulnerability in crypto: ecc - Fix carry overflow in vli multiplication. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <d11b2bb99bec1f5557c01cac42231e23745f49b8 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <b709e0e768766abe29a49e1c1922a1604be602f4 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <24a54dfa06d09813b4802a374fad3d2c0e16a884 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <677450e5ef850c4d28b7956aa01104548c2a894e || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <5275e0fca256d081e2e7d4ba3dd8216c6e50d44e || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <774ddddf5eb26eeca177350413e3e2bc50930ee9 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <ebaae7c4251cc0cdb2602f334d4f08a3e82d271e || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406 | d11b2bb99bec1f5557c01cac42231e23745f49b8, b709e0e768766abe29a49e1c1922a1604be602f4, 24a54dfa06d09813b4802a374fad3d2c0e16a884, 677450e5ef850c4d28b7956aa01104548c2a894e, 5275e0fca256d081e2e7d4ba3dd8216c6e50d44e, 774ddddf5eb26eeca177350413e3e2bc50930ee9, ebaae7c4251cc0cdb2602f334d4f08a3e82d271e, 27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <d11b2bb99bec1f5557c01cac42231e23745f49b8 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <b709e0e768766abe29a49e1c1922a1604be602f4 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <24a54dfa06d09813b4802a374fad3d2c0e16a884 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <677450e5ef850c4d28b7956aa01104548c2a894e || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <5275e0fca256d081e2e7d4ba3dd8216c6e50d44e || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <774ddddf5eb26eeca177350413e3e2bc50930ee9 || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <ebaae7c4251cc0cdb2602f334d4f08a3e82d271e || >=3c4b23901a0c766879dff680cd6bdab47bcdbbd2 <27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406 | d11b2bb99bec1f5557c01cac42231e23745f49b8, b709e0e768766abe29a49e1c1922a1604be602f4, 24a54dfa06d09813b4802a374fad3d2c0e16a884, 677450e5ef850c4d28b7956aa01104548c2a894e, 5275e0fca256d081e2e7d4ba3dd8216c6e50d44e, 774ddddf5eb26eeca177350413e3e2bc50930ee9, ebaae7c4251cc0cdb2602f334d4f08a3e82d271e, 27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.
Quoted source text, attributed separately from HOL analysis.