Description
In the Linux kernel, the following vulnerability has been resolved:

ipv6: avoid divide by zero in rt6_multipath_rebalance

rt6_multipath_rebalance() calculates the total eligible nexthop weight
in one pass and programs upper bounds in a second pass. Since
RTM_NEWROUTE is RTNL-free, a concurrent
ignore_routes_with_linkdown update can make the first pass return zero
while the second sees an eligible nexthop, causing
rt6_upper_bound_set() to divide by zero.

UBSAN: division-overflow in net/ipv6/route.c:4845:17
Oops: divide error: 0000 [#1] SMP KASAN NOPTI
rt6_upper_bound_set() net/ipv6/route.c:4845
rt6_multipath_rebalance()
fib6_add_rt2node()
ip6_route_multipath_add()
inet6_rtm_newroute()

Skip upper-bound calculation when the first pass reports a zero total.
This respects the lock-free performance considerations here and solves
insecure scenarios.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch It
AI Analysis

Impact

The Linux kernel’s IPv6 routing stack contains a logic flaw in rt6_multipath_rebalance. When a concurrent ignore_routes_with_linkdown update runs, the first pass of the algorithm can compute a total weight of zero while the second pass still sees an eligible next hop. This discrepancy leads rt6_upper_bound_set to divide by zero, causing a kernel panic (an Oops error). The vulnerability is exposed during processing of RTM_NEWROUTE netlink messages, so an attacker who can trigger such a routing update—typically with local or elevated privileges—can deliberately force the system to crash. The issue is resolved by skipping the upper-bound calculation when the first pass returns a zero total, preventing the division fault and the resulting fault in the kernel.

Affected Systems

The flaw exists in any Linux kernel build that has not yet embraced the upstream commit d2c26c2911dd1a363c488add4fb63eb5f0f28f87 (and related imports). Version ranges are not enumerated in the data, so every distribution that has not applied the patch may be vulnerable. The kernel family, regardless of vendor, is impacted.

Risk and Exploitability

An EPSS score of less than 1% and absence from the CISA KEV catalog imply that exploitation is currently considered rare. No CVSS score is provided, so the exact numerical severity cannot be stated; however, the resulting kernel panic represents a clear denial‑of‑service condition. Exploitation requires the ability to submit a crafted RTM_NEWROUTE message, which is generally restricted to privileged users. Local attackers can easily trigger the fault, while remote exploitation would depend on whether an attacker can influence netlink traffic—a scenario much less likely in hardened environments. Overall, the risk is high for affected systems but the observed likelihood of exploitation remains low.

Generated by OpenCVE AI on September 20, 2026 at 05:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that incorporates the rt6_multipath_rebalance fix (commit d2c26c2911dd1a363c488add4fb63eb5f0f28f87).
  • After installing the updated kernel, reboot the system so the new kernel image is actively running.
  • Continuously monitor kernel logs (e.g., dmesg or /var/log/kern.log) for division‑over‑flow or Oops messages, and apply any subsequent updates if additional issues arise.

Generated by OpenCVE AI on September 20, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369

Wed, 16 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid divide by zero in rt6_multipath_rebalance rt6_multipath_rebalance() calculates the total eligible nexthop weight in one pass and programs upper bounds in a second pass. Since RTM_NEWROUTE is RTNL-free, a concurrent ignore_routes_with_linkdown update can make the first pass return zero while the second sees an eligible nexthop, causing rt6_upper_bound_set() to divide by zero. UBSAN: division-overflow in net/ipv6/route.c:4845:17 Oops: divide error: 0000 [#1] SMP KASAN NOPTI rt6_upper_bound_set() net/ipv6/route.c:4845 rt6_multipath_rebalance() fib6_add_rt2node() ip6_route_multipath_add() inet6_rtm_newroute() Skip upper-bound calculation when the first pass reports a zero total. This respects the lock-free performance considerations here and solves insecure scenarios.
Title ipv6: avoid divide by zero in rt6_multipath_rebalance
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T08:48:26.343Z

Reserved: 2026-09-11T19:38:34.766Z

Link: CVE-2026-89790

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T09:17:09.827

Modified: 2026-09-16T09:17:09.827

Link: CVE-2026-89790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:45:16Z

Weaknesses
  • CWE-368

    Context Switching Race Condition