Integer overflow in Linux kernel - CVE-2026-64313
Published: July 27, 2026
Vulnerability identifier: #VU139667
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64313
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause incorrect cryptographic computation.
The vulnerability exists due to an integer overflow in crypto/ecc.c when performing elliptic curve multiplication. A local user can trigger the vulnerable arithmetic path to cause incorrect cryptographic computation.
Affected software
Linux kernel
How to mitigate CVE-2026-64313
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/24a54dfa06d09813b4802a374fad3d2c0e16a884
- https://git.kernel.org/stable/c/27b536a2ec8e2f85a0380c2d13c9ecbc7aaab406
- https://git.kernel.org/stable/c/5275e0fca256d081e2e7d4ba3dd8216c6e50d44e
- https://git.kernel.org/stable/c/677450e5ef850c4d28b7956aa01104548c2a894e
- https://git.kernel.org/stable/c/774ddddf5eb26eeca177350413e3e2bc50930ee9
- https://git.kernel.org/stable/c/b709e0e768766abe29a49e1c1922a1604be602f4
- https://git.kernel.org/stable/c/d11b2bb99bec1f5557c01cac42231e23745f49b8
- https://git.kernel.org/stable/c/ebaae7c4251cc0cdb2602f334d4f08a3e82d271e