Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-64313

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-64313

8 дней назад

A flaw was found in the Linux kernel's Elliptic Curve Cryptography (ECC) component. An attacker on an adjacent network could exploit an error in the very long integer (vli) multiplication's carry flag calculation. This mathematical inaccuracy in cryptographic operations could lead to high impact on confidentiality, integrity, and availability.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-64313

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-64313

7 дней назад

crypto: ecc - Fix carry overflow in vli multiplication

EPSS: Низкий
debian логотип

CVE-2026-64313

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: c ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-x49g-5fpg-2qxf

7 дней назад

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-64313

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.

CVSS3: 8.8
0%
Низкий
7 дней назад
redhat логотип
CVE-2026-64313

A flaw was found in the Linux kernel's Elliptic Curve Cryptography (ECC) component. An attacker on an adjacent network could exploit an error in the very long integer (vli) multiplication's carry flag calculation. This mathematical inaccuracy in cryptographic operations could lead to high impact on confidentiality, integrity, and availability.

CVSS3: 5.5
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-64313

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.

CVSS3: 8.8
0%
Низкий
7 дней назад
msrc логотип
CVE-2026-64313

crypto: ecc - Fix carry overflow in vli multiplication

0%
Низкий
7 дней назад
debian логотип
CVE-2026-64313

In the Linux kernel, the following vulnerability has been resolved: c ...

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-x49g-5fpg-2qxf

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.

CVSS3: 8.8
0%
Низкий
7 дней назад

Уязвимостей на страницу