-

CVE-2026-89790

ipv6: avoid divide by zero in rt6_multipath_rebalance

In the Linux kernel, the following vulnerability has been resolved:

ipv6: avoid divide by zero in rt6_multipath_rebalance

rt6_multipath_rebalance() calculates the total eligible nexthop weight
in one pass and programs upper bounds in a second pass. Since
RTM_NEWROUTE is RTNL-free, a concurrent
ignore_routes_with_linkdown update can make the first pass return zero
while the second sees an eligible nexthop, causing
rt6_upper_bound_set() to divide by zero.

UBSAN: division-overflow in net/ipv6/route.c:4845:17
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
  rt6_upper_bound_set() net/ipv6/route.c:4845
  rt6_multipath_rebalance()
  fib6_add_rt2node()
  ip6_route_multipath_add()
  inet6_rtm_newroute()

Skip upper-bound calculation when the first pass reports a zero total.
This respects the lock-free performance considerations here and solves
insecure scenarios.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bd11ff421d36abdb585b9104fa70057bf01b3110
Version < f30cf8fd9872299c0c27f9916252ba2b9f422dce
Status affected
Version bd11ff421d36abdb585b9104fa70057bf01b3110
Version < f82b5dbb2fef65b52a62d5ffe05e0483c4385a83
Status affected
Version bd11ff421d36abdb585b9104fa70057bf01b3110
Version < d2c26c2911dd1a363c488add4fb63eb5f0f28f87
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.098
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f30cf8fd9872299c0c27f9916252ba2b9f422dce
https://git.kernel.org/stable/c/f82b5dbb2fef65b52a62d5ffe05e0483c4385a83
https://git.kernel.org/stable/c/d2c26c2911dd1a363c488add4fb63eb5f0f28f87