Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93653.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-93653
Upstream
Published
2026-07-25T10:17:12Z
Modified
2026-08-28T17:47:48.405202984Z
Summary
CVE-2026-64313 affecting package kernel for versions less than 6.6.145.2-1
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: ecc - Fix carry overflow in vli multiplication

The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows.

The condition (r01.mhigh < product.mhigh) doesn't handle the case where r01.mhigh == product.mhigh and an additional carry exists from lower-bit overflow.

When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul6464() and add128128() helpers. It seems the check got lost in translation.

Add proper handling for this boundary by accounting for the carry from the lower addition.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.145.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-93653.json"