Back

HIGH

crypto: ecc - Fix carry overflow in vli multiplication

Published Jul 25, 2026

Description

The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows.

The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow.

When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation.

Add proper handling for this boundary by accounting for the carry from the lower addition.

Affected products

Remediation

No remediation recorded yet.

References (14)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Jul 25, 2026
Updated Aug 17, 2026
Reserved Jul 19, 2026

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Sep 3, 2026

Red Hat

Severity Moderate
Public date Jul 25, 2026
Bugzilla 2507085

ENISA EUVD

Assigner Linux
Published Jul 25, 2026
Updated Aug 17, 2026

GitHub

No data