CVE-2026-89790
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ipv6: avoid divide by zero in rt6_multipath_rebalance
rt6_multipath_rebalance() calculates the total eligible nexthop weight in one pass and programs upper bounds in a second pass. Since RTM_NEWROUTE is RTNL-free, a concurrent ignore_routes_with_linkdown update can make the first pass return zero while the second sees an eligible nexthop, causing rt6_upper_bound_set() to divide by zero.
UBSAN: division-overflow in net/ipv6/route.c:4845:17 Oops: divide error: 0000 [#1] SMP KASAN NOPTI rt6_upper_bound_set() net/ipv6/route.c:4845 rt6_multipath_rebalance() fib6_add_rt2node() ip6_route_multipath_add() inet6_rtm_newroute()
Skip upper-bound calculation when the first pass reports a zero total. This respects the lock-free performance considerations here and solves insecure scenarios.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | bd11ff421d36abdb585b9104fa70057bf01b3110 < f30cf8fd9872299c0c27f9916252ba2b9f422dce | affected |
| Linux | Linux | bd11ff421d36abdb585b9104fa70057bf01b3110 < f82b5dbb2fef65b52a62d5ffe05e0483c4385a83 | affected |
| Linux | Linux | bd11ff421d36abdb585b9104fa70057bf01b3110 < d2c26c2911dd1a363c488add4fb63eb5f0f28f87 | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f30cf8fd9872299c0c27f9916252ba2b9f422dce
- https://git.kernel.org/stable/c/f82b5dbb2fef65b52a62d5ffe05e0483c4385a83
- https://git.kernel.org/stable/c/d2c26c2911dd1a363c488add4fb63eb5f0f28f87
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.