Impact
The Linux kernel’s IPv6 routing stack contains a logic flaw in rt6_multipath_rebalance. When a concurrent ignore_routes_with_linkdown update runs, the first pass of the algorithm can compute a total weight of zero while the second pass still sees an eligible next hop. This discrepancy leads rt6_upper_bound_set to divide by zero, causing a kernel panic (an Oops error). The vulnerability is exposed during processing of RTM_NEWROUTE netlink messages, so an attacker who can trigger such a routing update—typically with local or elevated privileges—can deliberately force the system to crash. The issue is resolved by skipping the upper-bound calculation when the first pass returns a zero total, preventing the division fault and the resulting fault in the kernel.
Affected Systems
The flaw exists in any Linux kernel build that has not yet embraced the upstream commit d2c26c2911dd1a363c488add4fb63eb5f0f28f87 (and related imports). Version ranges are not enumerated in the data, so every distribution that has not applied the patch may be vulnerable. The kernel family, regardless of vendor, is impacted.
Risk and Exploitability
An EPSS score of less than 1% and absence from the CISA KEV catalog imply that exploitation is currently considered rare. No CVSS score is provided, so the exact numerical severity cannot be stated; however, the resulting kernel panic represents a clear denial‑of‑service condition. Exploitation requires the ability to submit a crafted RTM_NEWROUTE message, which is generally restricted to privileged users. Local attackers can easily trigger the fault, while remote exploitation would depend on whether an attacker can influence netlink traffic—a scenario much less likely in hardened environments. Overall, the risk is high for affected systems but the observed likelihood of exploitation remains low.
OpenCVE Enrichment